CVE-2026-84653
—CVSS 3.1
3.5 low
EPSS
<1%p8
Published
()
Modified
Description
Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.
- Vendors
- jenkins
- Products
- jenkins
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.