Remote Code Execution Vulnerability in Jenkins by CloudBees
CVE-2026-84645

Currently unrated

Key Information:

Vendor

Jenkins

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84645?

In Jenkins versions 2.579 and earlier, including LTS version 2.568.2, a significant vulnerability exists where certain objects are improperly handled as nested field values in user-submitted 'config.xml' documents. This allows for potential remote code execution via HTTP requests processed through Stapler, enabling attackers to exploit this oversight and execute arbitrary code on the server. Security best practices should be followed to mitigate this issue, and users are urged to review their configurations and apply updates where necessary.

Affected Version(s)

Jenkins 2.580

Jenkins 2.580

Jenkins 2.568.3 < 2.568.*

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.