Intel

AIKIDO-2026-668972

jenkins-core is vulnerable to Remote Code Execution

Remote Code ExecutionCVE-2026-84645 Published Yesterday

88

High Risk

This Affects:

JAVAjenkins-core
0.0.1 - 2.568.2
Fixed in 2.568.3
2.569 - 2.579
Fixed in 2.580
Are you affected? Scan for Free

TL;DR

Objects of types marked as storing their configuration in independent top-level files can appear as nested field values in user-submitted config.xml documents and then handle HTTP requests via Stapler. A crafted combination of such nested objects can reach an improperly protected Script Console and execute code on the controller. The fix prevents those persistence-root types from being deserialized as nested fields in other objects.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and users can submit or update job or global config.xml documents.

Background info

jenkins-core is vulnerable to Remote Code Execution in versions 0.0.1 - 2.568.2 and 2.569 - 2.579.

How to fix this

Upgrade the org.jenkins-ci.main:jenkins-core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform