• PoC PUBLIC

CVE-2026-84645: authenticated remote code execution in Jenkins Project Jenkins

A low-privilege user can execute arbitrary code on Jenkins servers by submitting crafted config.xml documents that cause objects to be treated as top-level Stapler handlers, leading to remote code execution (CVE-2026-84645). All Jenkins versions are listed as affected and no fixed release is recorded; an attacker needs a Jenkins account with the ability to submit configuration (a low-privilege account) or otherwise create configuration data that reaches Jenkins’ config.xml processing.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
8.8HIGH
EPSS
0.0079
CWE
CWE-94
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent — exploit code is public and no fixed version is available, and the flaw affects all Jenkins releases; reduce exposure and tighten access immediately.

What is CVE-2026-84645?

A low-privilege user can execute arbitrary code on Jenkins servers by submitting crafted config.xml documents that cause objects to be treated as top-level Stapler handlers, leading to remote code execution (CVE-2026-84645). All Jenkins versions are listed as affected and no fixed release is recorded; an attacker needs a Jenkins account with the ability to submit configuration (a low-privilege account) or otherwise create configuration data that reaches Jenkins’ config.xml processing.

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Jenkins Project Jenkins are affected?

BRANCHAFFECTEDFIXED
Jenkinsall versions

Is CVE-2026-84645 being exploited?

Public exploit code is available.

How to fix CVE-2026-84645

  1. Restrict access to Jenkins web UI and API to trusted networks and administrators.
  2. Disable or remove untrusted low-privilege accounts and block self-service account creation where possible.
  3. Monitor Jenkins logs for unexpected config.xml submissions and unusual Stapler request handling.
  4. Follow Jenkins project advisories and apply vendor fixes as soon as a patched release is published.

Frequently asked questions

Is CVE-2026-84645 being actively exploited?

Public exploit code is available for CVE-2026-84645; there is no CISA KEV listing, and no official public report of active exploitation is recorded as of 2026-09-29.

Which Jenkins versions are affected by CVE-2026-84645?

Jenkins is reported as affected in all versions in the supplied facts; no fixed versions are listed.

Is there a patch for CVE-2026-84645?

No fixed release is recorded in the provided data; apply mitigations and watch for an official patched Jenkins release.

Does CVE-2026-84645 require authentication?

Yes — the vulnerability requires a low-privilege Jenkins account capable of submitting config.xml-style configuration data.

References