Jenkins Configuration Update Vulnerability in Jenkins Software
CVE-2026-84651
Currently unrated
What is CVE-2026-84651?
In certain versions of Jenkins, a serious access control flaw exists within the REST API and CLI endpoints, allowing attackers with the Agent/Configure permission on one agent to overwrite configurations of another agent. By specifying the targeted agent's name in a submitted XML document, an attacker can gain control over the agent's settings, exposing sensitive information such as the inbound agent secret and environment variables. This presents a significant security risk as it could lead to unauthorized access and manipulation of resources.
Affected Version(s)
Jenkins 2.580
Jenkins 2.580
Jenkins 2.568.3 < 2.568.*