Vulnerability Bulletins

CVE-2026-84653

   
Affected software JENKINS
 
Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-84653