CVE-2026-84655: Jenkins
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses.
Affected products
- Jenkins Jenkins: up to and including 2.568.2; up to and including 2.579
Published 2026-09-02. Last modified 2026-09-15.