CVE-2026-84652
Received Received - Intake

Session Fixation in Jenkins via Remember Me Cookie

Vulnerability report for CVE-2026-84652, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Jenkins Project

Description

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which after the victim authenticates via the "remember me" cookie, grants the attacker access to Jenkins as that user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
jenkins jenkins to 2.580 (exc)
jenkins jenkins to 2.569 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Jenkins allows an attacker to hijack a user's session by exploiting the 'remember me' cookie. When a user logs in using this feature, their session ID is not rotated. An attacker who can serve content on the same site can set a known session cookie in the victim's browser. After the victim authenticates via the 'remember me' cookie, the attacker gains access to Jenkins as that user.

Impact Analysis

If you use Jenkins with the 'remember me' feature enabled, an attacker could gain unauthorized access to your Jenkins account. This could lead to data theft, unauthorized code execution, or further compromise of your Jenkins environment and connected systems.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements such as GDPR (data protection) or HIPAA (health information privacy). Organizations may face legal penalties, reputational damage, and loss of trust due to data breaches resulting from this issue.

Mitigation Strategies

Upgrade Jenkins to a version later than 2.579 or LTS 2.568.2 to ensure session rotation is enabled after authentication via the remember me cookie.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84652. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart