CVE-2026-84647: Jenkins Stapler vulnerability
In Stapler 2107.v8dfcbe8ed317 and earlier, except 2088.2093.vd7c3e58008a6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field type was not intended.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Staplerto a version that resolves this vulnerability.Fixed in 2107.v8dfcb_e8ed317 - Upgrade
Upgrade
Jenkinsto a version that resolves this vulnerability.Fixed in 2.579 - Upgrade
Upgrade
Jenkins LTSto a version that resolves this vulnerability.Fixed in 2.568.2 - Compensating control
Ensure the application does not allow attackers with Overall/Read permission to access the vulnerable form data binding features; restrict access to Overall/Read to trusted users only.
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs Overall/Read permission. The issue involves supplying form data that causes Stapler to instantiate configuration-related object types that are not compatible with the intended field type.
Which Stapler versions are affected?
Stapler 2107.v8dfcb_e8ed317 and earlier are affected, except for 2088.2093.vd7c3e58008a_6. The issue is included in Jenkins 2.579 and earlier, and Jenkins LTS 2.568.2 and earlier.