CVE-2026-84651: Jenkins

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML document, allowing attackers with Agent/Configure permission on one agent to take over a different agent, gaining control of its configuration and obtaining access to its inbound agent secret and environment variables.

Affected products

  • Jenkins Jenkins: before 2.568.3 (fixed in 2.568.3); before 2.580 (fixed in 2.580)

Published 2026-09-02. Last modified 2026-09-11.