CVE-2026-84653: Low severity Jenkins Jenkins vulnerability
Published Sep 2, 2026
·Updated
Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.
Affected Software
4 affected components
Jenkins Jenkins>=2.421<=2.579
Jenkins Jenkins LTS>=2.426.1<=2.568.2
Jenkins Jenkins>=2.421<=2.579
Jenkins Jenkins>=2.426.1<=2.568.2
Event History
Sep 2, 2026
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
Description
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must already have Jenkins Overall/Manage permission. The issue allows that user to modify Appearance configuration options that should be restricted.
2
Which Jenkins releases are affected?
Jenkins 2.579 and earlier are affected, as are Jenkins LTS 2.568.2 and earlier.