LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-84650

Published
CVSS8.8
Severityhigh
WeaknessCWE-502
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-84650

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-84650.