{"id":"CVE-2026-84648","title":"In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in co…","summary":"In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in co…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-79"],"vendor":"jenkins","product":"jenkins","affected":["jenkins < 2.568.3","jenkins < 2.580"],"patched":["jenkins 2.580"],"published":"2026-09-02","updated":"2026-09-11","sourceUpdated":"2026-09-11T21:14:57.963","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84648","references":[{"url":"https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-3967","label":"jenkinsci-cert@googlegroups.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-02T17:39:10.453508Z"},"ingestedAt":"2026-09-14T13:15:02.806Z","epss":0.00436,"epssPercentile":0.37367,"slug":"CVE-2026-84648","body":"## Overview\n\nIn Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes.\n\n## Affected\n\n- `jenkins < 2.568.3`\n- `jenkins < 2.580`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `jenkins 2.580`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}