---
id: CVE-2026-84650
title: >-
  In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot
  be excluded from deserialization, allowing attackers able to submit
  configuration updates to specify the values of transient fields that will be
  deserialized,…
summary: >-
  In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot
  be excluded from deserialization, allowing attackers able to submit
  configuration updates to specify the values of transient fields that will be
  deserialized,…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
  - CWE-566
vendor: jenkins
product: jenkins
affected:
  - jenkins < 2.568.3
  - jenkins < 2.580
patched:
  - jenkins 2.580
published: '2026-09-02'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T21:16:02.740'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84650'
references:
  - url: 'https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-4032'
    label: jenkinsci-cert@googlegroups.com
tags:
  - nvd
  - cve.org
epss: 0.00468
epssPercentile: 0.37917
ingestedAt: '2026-09-12T00:03:49.032Z'
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-02T17:37:41.225362Z'
---

## Overview

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.

## Affected

- `jenkins < 2.568.3`
- `jenkins < 2.580`

## Remediation

Upgrade past the affected range:

- `jenkins 2.580`
