Intel

AIKIDO-2026-132243

jenkins-core is vulnerable to Deserialization of Untrusted Data

Deserialization of Untrusted DataCVE-2026-84647 Published Yesterday

88

High Risk

This Affects:

JAVAjenkins-core
0.0.1 - 2.568.2
Fixed in 2.568.3
2.569 - 2.579
Fixed in 2.580
Are you affected? Scan for Free

TL;DR

Stapler form data binding does not restrict instantiated object types to those compatible with the expected field type. An attacker with Overall/Read permission can instantiate configuration-related types that the field was not intended to accept. The fix limits form binding to types compatible with the declared field type.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and users with Overall/Read permission can submit form data that Stapler binds into configuration objects.

Background info

jenkins-core is vulnerable to Deserialization of Untrusted Data in versions 0.0.1 - 2.568.2 and 2.569 - 2.579.

How to fix this

Upgrade the org.jenkins-ci.main:jenkins-core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform