PatchSiren cyber security CVE debrief
CVE-2026-84677 Jenkins Project CVE debrief
The CVE-2026-84677 vulnerability affects Jenkins update-center2 versions 3.18.3 and earlier. It is a stored cross-site scripting (XSS) vulnerability that allows attackers to provide a plugin for hosting, leading to potential exploitation. The vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. Jenkins administrators, security teams, and developers hosting plugins for Jenkins update-center2 should be aware of this vulnerability and take necessary actions to mitigate the risk. Evidence from official CVE Program record and NIST NVD detail page indicates a stored cross-site scripting (XSS) vulnerability in Jenkins update-center2 3.18.3 and earlier. The vulnerability is exploitable by attackers able to provide a plugin for hosting. Plugin-provided values (plugin names, descriptions, and version metadata) are not escaped on plugin download index pages.
- Vendor
- Jenkins Project
- Product
- Jenkins update-center2
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-03
Who should care
Jenkins administrators, security teams, and developers hosting plugins for Jenkins update-center2 should be aware of this vulnerability and take necessary actions to mitigate the risk. They should review and update Jenkins update-center2 to version 3.18.4 or later, restrict plugin installation to trusted sources, monitor plugin download index pages for suspicious activity, and implement additional security controls for Jenkins instances. Additionally, they should verify the authenticity of plugins and ensure that they are from trusted sources before installing them. It is also recommended to implement compensating controls for exposed systems while remediation is scheduled and verified, and to track exceptions, retest remediated assets, and close the item only after evidence is documented. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated to ensure effective mitigation of the vulnerability. This may involve coordinating with Jenkins administrators, security teams, and developers to ensure that all necessary steps are taken to mitigate the vulnerability. By taking these steps, organizations can help prevent exploitation of this vulnerability and reduce the risk of a security breach. The vulnerability can be mitigated by implementing additional security controls, such as monitoring and detection, and by ensuring that all Jenkins instances are up-to-date and patched. It is also important to review compensating controls for exposed systems while remediation is scheduled and verified, and to track exceptions, retest remediated assets, and close the item only after evidence is documented. This will help ensure that the vulnerability is properly mitigated and that the risk of a security breach is reduced. The Jenkins update-center2 vulnerability can be mitigated by taking a proactive and multi-faceted approach to security, including updating Jenkins update-center2 to version 3.18.4 or later, restricting plugin installation to trusted sources, monitoring plugin download index pages for suspicious activity, and implementing additional security controls for Jenkins instances. By taking these steps, organizations,
Technical summary
Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting. This vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. The vulnerability can be mitigated by updating Jenkins update-center2 to version 3.18.4 or later, restricting plugin installation to trusted sources, monitoring plugin download index pages for suspicious activity, and implementing additional security controls for Jenkins instances.
Defensive priority
Medium-severity XSS vulnerability in Jenkins update-center2, exploitable by attackers able to provide a plugin for hosting.
Recommended defensive actions
- Review and update Jenkins update-center2 to version 3.18.4 or later
- Restrict plugin installation to trusted sources
- Monitor plugin download index pages for suspicious activity
- Implement additional security controls for Jenkins instances
- Verify plugin authenticity before installation
- Track exceptions and retest remediated assets
- Review compensating controls for exposed systems while remediation is scheduled and verified
Evidence notes
Evidence from official CVE Program record and NIST NVD detail page indicates a stored cross-site scripting (XSS) vulnerability in Jenkins update-center2 3.18.3 and earlier. The vulnerability is exploitable by attackers able to provide a plugin for hosting. Plugin-provided values (plugin names, descriptions, and version metadata) are not escaped on plugin download index pages.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-84677 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-84677
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-84677 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84677
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.jenkins.io/security/advisory/2026-09-02/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.