CVE-2026-84651EPSS p21.5%
CVE-2026-84651CVE-2026-84651
jenkins / jenkins
Description
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML document, allowing attackers with Agent/Configure permission on one agent to take over a different agent, gaining control of its configuration and obtaining access to its inbound agent secret and environment variables.
Scoring
| CVSS | 6.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| EPSS | 0.31% probability of exploitation · percentile 21.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-11 |