CVE-2026-84653: Jenkins

Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.

Affected products

  • Jenkins Jenkins: from 2.421, up to and including 2.579; from 2.426.1, up to and including 2.568.2

Published 2026-09-02. Last modified 2026-09-15.