CVE-2026-84649: CSRF

Published Sep 2, 2026
·
Updated

In Stapler 1839.ved17667baeb5 through 2107.v8dfcbe8ed317 (both inclusive), except 2088.2093.vd7c3e58008a6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for the targeted user's session and perform actions on their behalf.

Affected Software

2 affected components
Jenkins>=2.447<=2.579
Jenkins>=2.452.1<=2.568.2

Event History

Sep 2, 2026
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
Description

Frequently Asked Questions

1

Who can realistically exploit this issue?

An attacker must be able to control a page hosted on the same site as the Jenkins instance. They can then target a user who has an active Jenkins session.

2

What does an attacker need to obtain before acting as the targeted user?

The attacker needs to retrieve a valid CSRF crumb for the targeted user's session from the affected dynamically generated JavaScript endpoint. The exposed crumb can be used to perform actions on that user's behalf.

3

Which installations should be treated as affected?

Affected Stapler versions are 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317, inclusive, except 2088.2093.vd7c3e58008a_6. These versions are included in Jenkins 2.447 through 2.579 and LTS 2.452.1 through 2.568.2, inclusive.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203