CVE-2026-84648: XSS
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes.
Affected Software
Event History
Frequently Asked Questions
Who can realistically exploit this issue?
An attacker needs control of a Jenkins agent process so they can influence log record metadata such as the source, level, or timestamp. This is a stored XSS issue affecting users who later view the system log.
Are default Jenkins installations affected?
The provided information identifies affected Jenkins versions but does not state whether a particular default configuration is required. Exposure depends on use of the system log viewer and whether an attacker can control an agent process.
What versions are affected?
Jenkins 2.579 and earlier, including LTS 2.568.2 and earlier, are affected.