{"id":"CVE-2026-84653","title":"Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify App…","summary":"Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify App…","severity":"low","cvss":3.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N","cwe":["CWE-862"],"vendor":"jenkins","product":"jenkins","affected":["jenkins >= 2.421, <= 2.579","jenkins >= 2.426.1, <= 2.568.2"],"published":"2026-09-02","updated":"2026-09-15","sourceUpdated":"2026-09-15T18:15:37.527","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84653","references":[{"url":"https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-3981","label":"jenkinsci-cert@googlegroups.com"}],"tags":["nvd"],"epss":0.00272,"epssPercentile":0.19824,"ingestedAt":"2026-09-15T18:41:59.124Z","slug":"CVE-2026-84653","body":"## Overview\n\nJenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.\n\n## Affected\n\n- `jenkins >= 2.421, <= 2.579`\n- `jenkins >= 2.426.1, <= 2.568.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":19,"depthScoreParts":{"impact":19.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}