Intel

AIKIDO-2026-846869

jenkins-core is vulnerable to Improper Access Control

Improper Access ControlCVE-2026-84654 Published Yesterday

43

Medium Risk

This Affects:

JAVAjenkins-core
0.0.1 - 2.568.2
Fixed in 2.568.3
2.569 - 2.579
Fixed in 2.580
Are you affected? Scan for Free

TL;DR

Stapler form data binding can set public static fields on bound configuration objects. An attacker who can submit configuration forms can alter global static state through those fields, affecting behavior instance-wide. The fix blocks form data binding from setting public static fields.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and users can submit configuration forms bound by Stapler.

Background info

jenkins-core is vulnerable to Improper Access Control in versions 0.0.1 - 2.568.2 and 2.569 - 2.579.

How to fix this

Upgrade the org.jenkins-ci.main:jenkins-core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform