CVE-2026-84649
Received
Received - Intake
CSRF Token Exposure in Jenkins Stapler
Vulnerability report for CVE-2026-84649, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-02
Last updated on: 2026-09-02
Assigner: Jenkins Project
Description
Description
In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for the targeted user's session and perform actions on their behalf.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| stapler | stapler | From 1839.ved17667b_a_eb_5 (inc) to 2107.v8dfcb_e8ed317 (inc) |
| jenkins | jenkins | From 2.447 (inc) to 2.579 (inc) |
| jenkins | jenkins | From 2.452.1 (inc) to 2.568.2 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |