CVE-2026-84648
Received Received - Intake

Stored XSS in Jenkins Due to Unescaped Log Metadata

Vulnerability report for CVE-2026-84648, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Jenkins Project

Description

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
jenkins jenkins to 2.580 (exc)
jenkins jenkins_lts to 2.569 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) issue in Jenkins versions 2.579 and earlier, as well as LTS 2.568.2 and earlier. The system log viewer fails to escape log record metadata such as source, level, and timestamp, allowing attackers who control agent processes to inject malicious scripts.

Detection Guidance

Check Jenkins version with 'java -jar jenkins.war --version' or via 'Manage Jenkins > System Information'. If version is 2.579 or earlier (LTS 2.568.2 or earlier), the system is vulnerable.

Impact Analysis

Attackers could exploit this to execute arbitrary JavaScript in the context of a user's browser session when viewing logs. This may lead to session hijacking, unauthorized actions on behalf of the user, or theft of sensitive data like credentials or session tokens.

Compliance Impact

This XSS vulnerability could compromise data confidentiality and integrity, violating GDPR's principles of data protection and HIPAA's requirements for safeguarding protected health information. Organizations may face compliance violations if user data is exposed due to this flaw.

Mitigation Strategies

Upgrade Jenkins to version 2.580 or later (LTS 2.568.3 or later) immediately. Restart the Jenkins service after upgrade. Ensure no untrusted agents have access to the system log viewer.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84648. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart