Object Instantiation Vulnerability in Jenkins by Stapler
CVE-2026-84647

Currently unrated

Key Information:

Vendor

Jenkins

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84647?

In Stapler versions 2107.v8dfcb_e8ed317 and earlier, as well as the Jenkins versions 2.579 and LTS 2.568.2, there exists a vulnerability that allows inappropriate object instantiation through form data binding. This occurs because Stapler does not enforce restrictions on the types of objects that can be created, permitting attackers with Overall/Read permissions to create objects for configuration types that were not originally intended for that field. This flaw can lead to unauthorized configuration manipulations, potentially compromising the security posture of the Jenkins instance.

Affected Version(s)

Jenkins 2.580

Jenkins 2.580

Jenkins 2.568.3 < 2.568.*

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.