ZeroHour

CVE-2026-84653

CVSS 3.1
3.5 low
EPSS
<1%p8
Published
()
Modified
Description

Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.

Vendors
jenkins
Products
jenkins
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.