ZeroHour

CVE-2026-84646

CVSS 3.1
4.3 medium
EPSS
<1%p15
Published
()
Modified
Description

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.

Vendors
jenkins
Products
jenkins
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.