CVE-2026-84653
Jenkins vulnerability analysis and mitigation

Overview

CVE-2026-84653 is an incorrect permission check vulnerability (SECURITY-3981) in the Jenkins Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options beyond their authorized scope. It affects Jenkins 2.421 through 2.579 (inclusive) and LTS 2.426.1 through 2.568.2 (inclusive). The vulnerability was disclosed on September 2, 2026, as part of a broader Jenkins security advisory. It carries a CVSS v3.1 base score of 3.5 (Low/Medium) (Jenkins Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): Jenkins does not correctly enforce per-option permission checks on the Appearance configuration page introduced in version 2.421. An authenticated attacker with the Overall/Manage permission can submit configuration changes to Appearance options that should require a higher privilege level (e.g., Overall/Administer). The practical impact is plugin-dependent — for instance, if the Simple Theme Plugin is installed, an attacker could specify URLs for JavaScript resources loaded on every Jenkins page, potentially enabling a stored cross-site scripting (XSS) attack against other users. No public proof-of-concept exploit code has been identified (Jenkins Advisory, GitHub Advisory).

Impact

Successful exploitation allows an attacker with Overall/Manage permission to modify Appearance configuration settings they should not have access to, resulting in low confidentiality and low integrity impact with no direct availability impact. The most significant risk arises when plugins like Simple Theme Plugin are installed, as an attacker could inject malicious JavaScript URLs into every Jenkins page, leading to a stored XSS condition that could compromise other users' sessions or credentials. The scope of impact is limited to the Jenkins instance itself and does not directly enable lateral movement or remote code execution on its own (Jenkins Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the advisory date (Feedly). The vulnerability requires the attacker to already hold Overall/Manage permission and requires user interaction (UI:R), limiting its exploitability. The EPSS score is approximately 0.164–0.184%, placing it in a low percentile for near-term exploitation likelihood. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Identify a target: Locate a Jenkins instance running versions 2.421–2.579 or LTS 2.426.1–2.568.2 with the Simple Theme Plugin (or similar appearance-modifying plugin) installed.
  2. Obtain Overall/Manage credentials: Authenticate to Jenkins using an account that holds the Overall/Manage permission but not Overall/Administer.
  3. Navigate to Appearance configuration: Access the Jenkins Appearance configuration page (typically at /manage/appearance or equivalent) using the authenticated session.
  4. Submit unauthorized configuration: Modify Appearance settings — for example, if Simple Theme Plugin is present, specify a URL pointing to an attacker-controlled JavaScript resource in the theme configuration field.
  5. Trigger XSS execution: Once the malicious JavaScript URL is saved, any Jenkins user who loads a Jenkins page will execute the attacker's script, potentially allowing session hijacking, credential theft, or further actions on behalf of the victim (Jenkins Advisory).

Indicators of compromise

  • Logs: Jenkins audit logs showing Overall/Manage-level users submitting POST requests to the Appearance configuration endpoint (e.g., /manage/appearance/configure) with unexpected parameter values.
  • Configuration Changes: Unexpected or unauthorized changes to Jenkins Appearance settings, particularly theme-related fields referencing external or unknown JavaScript/CSS URLs.
  • Network: Outbound HTTP requests from Jenkins users' browsers to unfamiliar external domains serving JavaScript resources, potentially indicating injected theme scripts are loading.
  • File System: Changes to Jenkins configuration files related to appearance/theme settings (e.g., config.xml entries for Simple Theme Plugin) with externally hosted resource URLs not previously configured by administrators.

Mitigation and workarounds

Jenkins has released fixed versions: Jenkins 2.580 (weekly) and LTS 2.568.3, both of which ensure each Appearance configuration option is only accessible to users with the required permission. Administrators should upgrade to these versions immediately. As a short-term workaround, restrict the Overall/Manage permission to fully trusted users only, and audit installed plugins (especially Simple Theme Plugin) for unauthorized configuration changes. Monitor audit logs for unexpected Appearance configuration modifications (Jenkins Advisory).

Community reactions

The vulnerability was disclosed as part of a large Jenkins security advisory on September 2, 2026, covering over 30 CVEs across Jenkins core and multiple plugins. The advisory was picked up by security aggregators including AUSCERT (ESB-2026.10414), Tenable, and the OSS-Security mailing list. Community reaction has been focused primarily on the higher-severity vulnerabilities in the same advisory (e.g., the deserialization RCE CVE-2026-84645), with CVE-2026-84653 receiving less individual attention due to its lower CVSS score and prerequisite of an already-privileged account (Jenkins Advisory).

Additional resources


SourceThis report was generated using AI

Related Jenkins vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84654MEDIUM5.4
  • Jenkins logoJenkins
  • jenkins
NoYesSep 02, 2026
CVE-2026-84656MEDIUM4.3
  • Jenkins logoJenkins
  • jenkins
NoYesSep 02, 2026
CVE-2026-84655MEDIUM4.3
  • Jenkins logoJenkins
  • jenkins
NoYesSep 02, 2026
CVE-2026-84657MEDIUM4.2
  • Jenkins logoJenkins
  • jenkins
NoYesSep 02, 2026
CVE-2026-84653LOW3.5
  • Jenkins logoJenkins
  • jenkins
NoYesSep 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management