Deserialization Flaw in Jenkins Affects User Objects
CVE-2026-84646

Currently unrated

Key Information:

Vendor

Jenkins

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84646?

In Jenkins versions 2.579 and earlier, as well as LTS 2.568.2 and earlier, a deserialization flaw allows user objects to be represented as nested field values within other deserialized XML objects. This enables attackers with Overall/Read permission to exploit the system by submitting specially crafted XML payloads, effectively creating unauthorized user objects and potentially compromising system integrity.

Affected Version(s)

Jenkins 2.580

Jenkins 2.580

Jenkins 2.568.3 < 2.568.*

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.