Form Data Binding Vulnerability in Jenkins Stapler by CloudBees
CVE-2026-84654

Currently unrated

Key Information:

Vendor

Jenkins

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84654?

A vulnerability exists in Jenkins Stapler versions 2107.v8dfcb_e8ed317 and earlier, along with Jenkins versions 2.579 and LTS 2.568.2 and earlier. This flaw allows attackers to manipulate public static fields within configuration objects by submitting malicious configuration forms, leading to potential global changes across the Jenkins instance. Addressing this issue is critical to maintaining the security and integrity of Jenkins environments.

Affected Version(s)

Jenkins 2.580

Jenkins 2.580

Jenkins 2.568.3 < 2.568.*

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.