Intel

AIKIDO-2026-163590

jenkins-core is vulnerable to Session Fixation

Session FixationCVE-2026-84652 Published Yesterday

88

High Risk

This Affects:

JAVAjenkins-core
0.0.1 - 2.568.2
Fixed in 2.568.3
2.569 - 2.579
Fixed in 2.580
Are you affected? Scan for Free

TL;DR

Authentication through the "remember me" cookie does not rotate the existing session. An attacker who can set a known session cookie on the same site can have that session become authenticated when the victim is re-authenticated from the persistent cookie. The fix invalidates and rotates the existing session when authenticating via the remember-me cookie.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and attackers can serve content on the same site as Jenkins to set a victim session cookie.

Background info

jenkins-core is vulnerable to Session Fixation in versions 0.0.1 - 2.568.2 and 2.569 - 2.579.

How to fix this

Upgrade the org.jenkins-ci.main:jenkins-core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform