Improper access control in Jenkins and Jenkins LTS - CVE-2026-84651
Published: September 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to insufficient validation of agent configuration updates. A remote user can take over a different agent, gain control of its configuration and obtain access to its inbound agent secret and environment variables.
Affected software
Jenkins LTS
How to mitigate CVE-2026-84651
Jenkins LTS - update to 2.568.3