CVE-2026-84653 PUBLISHED

Assigner: jenkins
Reserved: 01.09.2026 Published: 02.09.2026 Updated: 02.09.2026

Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.

Product Status

Vendor Jenkins Project
Product Jenkins
Versions Default: affected
  • unaffected from 2.580 to * (excl.)
  • unaffected from 2.568.3 to 2.568.* (excl.)

References