PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84677 Jenkins Project CVE debrief

The CVE-2026-84677 vulnerability affects Jenkins update-center2 versions 3.18.3 and earlier. It is a stored cross-site scripting (XSS) vulnerability that allows attackers to provide a plugin for hosting, leading to potential exploitation. The vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. Jenkins administrators, security teams, and developers hosting plugins for Jenkins update-center2 should be aware of this vulnerability and take necessary actions to mitigate the risk. Evidence from official CVE Program record and NIST NVD detail page indicates a stored cross-site scripting (XSS) vulnerability in Jenkins update-center2 3.18.3 and earlier. The vulnerability is exploitable by attackers able to provide a plugin for hosting. Plugin-provided values (plugin names, descriptions, and version metadata) are not escaped on plugin download index pages.

Vendor
Jenkins Project
Product
Jenkins update-center2
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-03
Advisory published
2026-09-02
Advisory updated
2026-09-03

Who should care

Jenkins administrators, security teams, and developers hosting plugins for Jenkins update-center2 should be aware of this vulnerability and take necessary actions to mitigate the risk. They should review and update Jenkins update-center2 to version 3.18.4 or later, restrict plugin installation to trusted sources, monitor plugin download index pages for suspicious activity, and implement additional security controls for Jenkins instances. Additionally, they should verify the authenticity of plugins and ensure that they are from trusted sources before installing them. It is also recommended to implement compensating controls for exposed systems while remediation is scheduled and verified, and to track exceptions, retest remediated assets, and close the item only after evidence is documented. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated to ensure effective mitigation of the vulnerability. This may involve coordinating with Jenkins administrators, security teams, and developers to ensure that all necessary steps are taken to mitigate the vulnerability. By taking these steps, organizations can help prevent exploitation of this vulnerability and reduce the risk of a security breach. The vulnerability can be mitigated by implementing additional security controls, such as monitoring and detection, and by ensuring that all Jenkins instances are up-to-date and patched. It is also important to review compensating controls for exposed systems while remediation is scheduled and verified, and to track exceptions, retest remediated assets, and close the item only after evidence is documented. This will help ensure that the vulnerability is properly mitigated and that the risk of a security breach is reduced. The Jenkins update-center2 vulnerability can be mitigated by taking a proactive and multi-faceted approach to security, including updating Jenkins update-center2 to version 3.18.4 or later, restricting plugin installation to trusted sources, monitoring plugin download index pages for suspicious activity, and implementing additional security controls for Jenkins instances. By taking these steps, organizations,

Technical summary

Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting. This vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. The vulnerability can be mitigated by updating Jenkins update-center2 to version 3.18.4 or later, restricting plugin installation to trusted sources, monitoring plugin download index pages for suspicious activity, and implementing additional security controls for Jenkins instances.

Defensive priority

Medium-severity XSS vulnerability in Jenkins update-center2, exploitable by attackers able to provide a plugin for hosting.

Recommended defensive actions

  • Review and update Jenkins update-center2 to version 3.18.4 or later
  • Restrict plugin installation to trusted sources
  • Monitor plugin download index pages for suspicious activity
  • Implement additional security controls for Jenkins instances
  • Verify plugin authenticity before installation
  • Track exceptions and retest remediated assets
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

Evidence from official CVE Program record and NIST NVD detail page indicates a stored cross-site scripting (XSS) vulnerability in Jenkins update-center2 3.18.3 and earlier. The vulnerability is exploitable by attackers able to provide a plugin for hosting. Plugin-provided values (plugin names, descriptions, and version metadata) are not escaped on plugin download index pages.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84677 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84677

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84677 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84677

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.