Jenkins Project Jenkins

14 known vulnerabilities in Jenkins Project Jenkins, 1 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2024-23897 CVSS 9.8 critical · actively exploited Jenkins Command Line Interface (CLI) Path Traversal Vulnerability

Latest vulnerabilities

  • CVE-2026-84657 CVSS 4.2 medium In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s…
  • CVE-2026-84656 CVSS 4.3 medium A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least…
  • CVE-2026-84655 CVSS 4.3 medium Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST…
  • CVE-2026-84654 CVSS 5.4 medium In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and…
  • CVE-2026-84653 CVSS 3.5 low Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in…
  • CVE-2026-84652 CVSS 7.3 high In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember…
  • CVE-2026-84651 CVSS 6.3 medium In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a…
  • CVE-2026-84650 CVSS 8.8 high In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able…
  • CVE-2026-84649 CVSS 8.8 high In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447…
  • CVE-2026-84648 CVSS 8.8 high In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and…
  • CVE-2026-84647 CVSS 8.8 high In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and…
  • CVE-2026-84646 CVSS 4.3 medium In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects…
  • CVE-2026-84645 CVSS 8.8 high In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level…
  • CVE-2024-23897 CVSS 9.8 critical · actively exploited Jenkins Command Line Interface (CLI) Path Traversal Vulnerability