CVE-2026-84646
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.
- Published Sep 2, 2026
- CVSS 4.3 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)