Object Serialization Vulnerability in Jenkins from CloudBees
CVE-2026-84655
Currently unrated
What is CVE-2026-84655?
The identified security issue within Jenkins versions 2.579 and earlier, along with LTS 2.568.2 and earlier, involves inadequate escaping of map keys during the serialization of objects to JSON and Python via its REST API. This oversight enables attackers who can manipulate map property names to inject arbitrary fields into the API responses. Such vulnerabilities can potentially lead to unauthorized data exposure or unwanted behavior within applications, emphasizing the need for prompt remediation and security enhancements.
Affected Version(s)
Jenkins 2.580
Jenkins 2.580
Jenkins 2.568.3 < 2.568.*