DIRAS TAKE
Urgent — exploit code is public and no fixed version is available, and the flaw affects all Jenkins releases; reduce exposure and tighten access immediately.
What is CVE-2026-84645?
A low-privilege user can execute arbitrary code on Jenkins servers by submitting crafted config.xml documents that cause objects to be treated as top-level Stapler handlers, leading to remote code execution (CVE-2026-84645). All Jenkins versions are listed as affected and no fixed release is recorded; an attacker needs a Jenkins account with the ability to submit configuration (a low-privilege account) or otherwise create configuration data that reaches Jenkins’ config.xml processing.
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Jenkins Project Jenkins are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Jenkins | all versions |
Is CVE-2026-84645 being exploited?
Public exploit code is available.
How to fix CVE-2026-84645
- Restrict access to Jenkins web UI and API to trusted networks and administrators.
- Disable or remove untrusted low-privilege accounts and block self-service account creation where possible.
- Monitor Jenkins logs for unexpected config.xml submissions and unusual Stapler request handling.
- Follow Jenkins project advisories and apply vendor fixes as soon as a patched release is published.
Frequently asked questions
Is CVE-2026-84645 being actively exploited?
Public exploit code is available for CVE-2026-84645; there is no CISA KEV listing, and no official public report of active exploitation is recorded as of 2026-09-29.
Which Jenkins versions are affected by CVE-2026-84645?
Jenkins is reported as affected in all versions in the supplied facts; no fixed versions are listed.
Is there a patch for CVE-2026-84645?
No fixed release is recorded in the provided data; apply mitigations and watch for an official patched Jenkins release.
Does CVE-2026-84645 require authentication?
Yes — the vulnerability requires a low-privilege Jenkins account capable of submitting config.xml-style configuration data.
References
- nvd.nist.gov/vuln/detail/CVE-2026-84645
- cve.org/CVERecord?id=CVE-2026-84645
- jenkins.io/security/advisory/2026-09-02/#SECURITY-3972
- All Jenkins Project CVEs on CVE Radar
- CVEs published in September 2026