CVE-2026-84652: Jenkins Jenkins vulnerability

Published Sep 2, 2026
·
Updated

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which after the victim authenticates via the "remember me" cookie, grants the attacker access to Jenkins as that user.

Affected Software

2 affected components
Jenkins Jenkins<=2.579
Jenkins Jenkins LTS<=2.568.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Jenkins to a version that resolves this vulnerability.

    Fixed in 2.579
  2. Upgrade

    Upgrade Jenkins LTS to a version that resolves this vulnerability.

    Fixed in 2.568.2

Event History

Sep 2, 2026
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
Description

Frequently Asked Questions

1

Who is exposed to this issue?

Jenkins instances running version 2.579 or earlier, or Jenkins LTS 2.568.2 or earlier, are affected. Exploitation also requires an attacker to be able to serve content on the same site as the Jenkins instance.

2

What must happen for an attacker to gain access?

The attacker must set a session cookie with a value they know in the victim's browser. If the victim later authenticates using a "remember me" cookie, Jenkins does not rotate that session, allowing the attacker to use the known session as the victim.

3

How can I tell whether this affects my authentication flow?

The described vulnerable flow specifically involves users being authenticated through Jenkins' "remember me" cookie. Review whether affected Jenkins instances allow or have users relying on remember-me authentication, in addition to checking the installed version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203