Stored Cross-Site Scripting Vulnerability in Jenkins by CloudBees
CVE-2026-84648

8.8HIGH

Key Information:

Vendor

Jenkins

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84648?

In affected versions of Jenkins, including 2.579 and earlier, and LTS 2.568.2 and earlier, the system log viewer fails to correctly escape log record metadata. This oversight allows attackers with control over agent processes to exploit the vulnerability, potentially injecting malicious scripts that result in stored cross-site scripting (XSS). Such vulnerabilities pose significant risks as they can lead to unauthorized access and information theft from user sessions.

Affected Version(s)

Jenkins 2.580

Jenkins 2.580

Jenkins 2.568.3 < 2.568.*

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.