CVE-2026-84646: Jenkins
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.
Affected products
- Jenkins Jenkins: before 2.568.3 (fixed in 2.568.3); before 2.580 (fixed in 2.580)
Published 2026-09-02. Last modified 2026-09-11.