Cross-Site Request Forgery Vulnerability in Jenkins Software
CVE-2026-84649

8.8HIGH

Key Information:

Vendor

Jenkins

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84649?

A security flaw exists in Jenkins software that affects several versions of the Stapler. This vulnerability allows an attacker to exploit the HTTP endpoint that serves dynamically generated JavaScript resources. By embedding the user's CSRF token as a string literal, attackers who control a page on the same site can access valid tokens for the targeted user's session. This could enable malicious actions on behalf of the user without their consent, underscoring the importance of secure token management and site integrity.

Affected Version(s)

Jenkins 2.580

Jenkins 2.580

Jenkins 0 < 2.447

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.