Intel

AIKIDO-2026-446154

jenkins-core is vulnerable to Deserialization of Untrusted Data

Deserialization of Untrusted DataCVE-2026-84650 Published Yesterday

88

High Risk

This Affects:

JAVAjenkins-core
0.0.1 - 2.568.2
Fixed in 2.568.3
2.569 - 2.579
Fixed in 2.580
Are you affected? Scan for Free

TL;DR

Transient fields cannot be excluded from deserialization during configuration updates. An attacker who can submit configuration updates can set transient field values that will be deserialized, with impact depending on how those fields are used. The fix adds a way to mark transient fields as non-deserializable so those values are ignored.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and users can submit configuration updates that are deserialized by Jenkins.

Background info

jenkins-core is vulnerable to Deserialization of Untrusted Data in versions 0.0.1 - 2.568.2 and 2.569 - 2.579.

How to fix this

Upgrade the org.jenkins-ci.main:jenkins-core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform