Jenkins Configuration Update Vulnerability in Jenkins Software
CVE-2026-84651

Currently unrated

Key Information:

Vendor

Jenkins

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84651?

In certain versions of Jenkins, a serious access control flaw exists within the REST API and CLI endpoints, allowing attackers with the Agent/Configure permission on one agent to overwrite configurations of another agent. By specifying the targeted agent's name in a submitted XML document, an attacker can gain control over the agent's settings, exposing sensitive information such as the inbound agent secret and environment variables. This presents a significant security risk as it could lead to unauthorized access and manipulation of resources.

Affected Version(s)

Jenkins 2.580

Jenkins 2.580

Jenkins 2.568.3 < 2.568.*

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.