Object Serialization Vulnerability in Jenkins from CloudBees
CVE-2026-84655

Currently unrated

Key Information:

Vendor

Jenkins

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84655?

The identified security issue within Jenkins versions 2.579 and earlier, along with LTS 2.568.2 and earlier, involves inadequate escaping of map keys during the serialization of objects to JSON and Python via its REST API. This oversight enables attackers who can manipulate map property names to inject arbitrary fields into the API responses. Such vulnerabilities can potentially lead to unauthorized data exposure or unwanted behavior within applications, emphasizing the need for prompt remediation and security enhancements.

Affected Version(s)

Jenkins 2.580

Jenkins 2.580

Jenkins 2.568.3 < 2.568.*

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.