PatchSiren cyber security CVE debrief
CVE-2026-84646 Jenkins Project CVE debrief
The CVE-2026-84646 vulnerability affects Jenkins 2.579 and earlier, LTS 2.568.2 and earlier. This vulnerability allows attackers with Overall/Read permission to create user objects by submitting crafted XML, potentially leading to unauthorized access or privilege escalation. The vulnerability has a CVSS score of 4.3 and a severity rating of MEDIUM. Jenkins administrators, security teams, and developers using Jenkins for CI/CD pipelines should be aware of this vulnerability and take necessary actions to mitigate the risk. The CVE record was published on 2026-09-02T16:17:29.313Z and has not been modified since then.
- Vendor
- Jenkins Project
- Product
- Jenkins
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-03
Who should care
Jenkins administrators, security teams, and developers using Jenkins for CI/CD pipelines should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes reviewing and applying vendor patches, restricting Overall/Read permission to trusted users, and monitoring Jenkins instance for suspicious user object creation activity. The vulnerability has a CVSS score of 4.3 and a severity rating of MEDIUM, indicating a medium-priority defensive review is recommended due to potential for user object creation and unauthorized access or privilege escalation. Evidence from official sources indicates a Medium-severity vulnerability in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, allowing attackers with Overall/Read permission to create user objects via crafted XML. Further review of vendor advisories and NVD details is warranted to ensure proper validation and sanitization of XML deserialization processes. Compensating controls for exposed systems while remediation is scheduled and verified can also help mitigate the risk. Checking relevant monitoring, detection, and logs for exposed assets that need extra review is also recommended. Asset inventory and source tracking can help identify potential vulnerabilities and prioritize remediation efforts. Rollback/change windows can also be used to minimize downtime and ensure smooth remediation. Monitoring and detection can help identify potential security incidents and ensure timely response and mitigation. Overall, a comprehensive review of the vulnerability and its potential impact on Jenkins deployments is necessary to ensure proper mitigation and remediation. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and planning vendor-supported updates or mitigations through normal change control where exposure is confirmed. A thorough review of compensating controls, monitoring, detection, and logs can help ensure that the vulnerability is properly mitigated and that security incidents are timely detected and responded to. By taking these steps, Jenkins administrators, security teams, and developers can help protect
Technical summary
A vulnerability in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, allows attackers with Overall/Read permission to create user objects by submitting crafted XML. This could potentially lead to unauthorized access or privilege escalation. The vulnerability has been assigned a CVSS score of 4.3 and a severity rating of MEDIUM. It is recommended that Jenkins administrators, security teams, and developers using Jenkins for CI/CD pipelines review and apply vendor patches for Jenkins 2.579 and earlier, LTS 2.568.2 and earlier. Additionally, restricting Overall/Read permission to trusted users and monitoring Jenkins instance for suspicious user object creation activity can help mitigate the risk.
Defensive priority
Medium-priority defensive review recommended due to potential for user object creation.
Recommended defensive actions
- Review and apply vendor patches for Jenkins 2.579 and earlier, LTS 2.568.2 and earlier.
- Restrict Overall/Read permission to trusted users.
- Monitor Jenkins instance for suspicious user object creation activity.
- Verify XML deserialization processes for proper validation and sanitization.
Evidence notes
Evidence from official sources indicates a Medium-severity vulnerability in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, allowing attackers with Overall/Read permission to create user objects via crafted XML. Further review of vendor advisories and NVD details is warranted.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-84646 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-84646
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-84646 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84646
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.jenkins.io/security/advisory/2026-09-02/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.