Jenkins Security Advisory 2026-09-02:
- (High) SECURITY-3972 / CVE-2026-84645: Deserialization
vulnerability
- (Medium) SECURITY-3908 / CVE-2026-84646: Lack of type
restriction in deserialization
- (High) SECURITY-3915 / CVE-2026-84647: Instantiation of any
types related to configuration
- (High) SECURITY-3967 / CVE-2026-84648: Stored XSS
vulnerability in system log viewer
- (High) SECURITY-3878 / CVE-2026-84649: Cross-origin exposure
of CSRF token
- (High) SECURITY-4032 / CVE-2026-84650: Unsafe deserialization
allows overwriting configuration
- (Medium) SECURITY-4025 / CVE-2026-84651: Unsafe
deserialization allows overwriting other agents
- (High) SECURITY-4016 / CVE-2026-84652: Session fixation
vulnerability
- (Medium) SECURITY-3981 / CVE-2026-84653: Incorrect permission
check in Appearance configuration page
- (Medium) SECURITY-3926 / CVE-2026-84654: Form submission data
binding can set static fields
- (Medium) SECURITY-3879 / CVE-2026-84655: Injection
vulnerability in REST API
- (Medium) SECURITY-4006 / CVE-2026-84656: Missing permission
check allows reading build parameters
- (Medium) SECURITY-4015 / CVE-2026-84657: Missing permission
check allows canceling builds