{"id":"CVE-2026-84649","title":"In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serv…","summary":"In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serv…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cvssSource":"adp","vendor":"Jenkins Project","product":"Jenkins","affected":["Jenkins (all versions)"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-02T17:38:27.819685Z"},"published":"2026-09-02","updated":"2026-09-17","sourceUpdated":"2026-09-17T19:06:19.098Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-84649","references":[{"url":"https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-3878","label":"Jenkins Security Advisory 2026-09-02"}],"tags":["cve.org"],"epss":0.00168,"epssPercentile":0.06568,"ingestedAt":"2026-09-17T19:26:25.326Z","slug":"CVE-2026-84649","body":"## Overview\n\nIn Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for the targeted user's session and perform actions on their behalf.\n\n## Affected\n\n- `Jenkins (all versions)`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}