Improper Permission Checks in Jenkins Configuration by CloudBees
CVE-2026-84653

Currently unrated

Key Information:

Vendor

Jenkins

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84653?

The Jenkins software has a vulnerability in the Appearance configuration page where permission checks are not adequately enforced. This issue enables users with Overall/Manage permissions to alter Appearance settings without the necessary access rights. As a result, unauthorized changes can be made to the Jenkins interface, potentially affecting the security and integrity of the Jenkins environment. It is essential for users to upgrade to the latest versions to mitigate this risk and enhance their security posture.

Affected Version(s)

Jenkins 2.580

Jenkins 2.580

Jenkins 0 < 2.421

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.