Deserialization Flaw in Jenkins Affects User Objects
CVE-2026-84646
Currently unrated
What is CVE-2026-84646?
In Jenkins versions 2.579 and earlier, as well as LTS 2.568.2 and earlier, a deserialization flaw allows user objects to be represented as nested field values within other deserialized XML objects. This enables attackers with Overall/Read permission to exploit the system by submitting specially crafted XML payloads, effectively creating unauthorized user objects and potentially compromising system integrity.
Affected Version(s)
Jenkins 2.580
Jenkins 2.580
Jenkins 2.568.3 < 2.568.*