
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84653 is an incorrect permission check vulnerability (SECURITY-3981) in the Jenkins Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options beyond their authorized scope. It affects Jenkins 2.421 through 2.579 (inclusive) and LTS 2.426.1 through 2.568.2 (inclusive). The vulnerability was disclosed on September 2, 2026, as part of a broader Jenkins security advisory. It carries a CVSS v3.1 base score of 3.5 (Low/Medium) (Jenkins Advisory, GitHub Advisory).
The root cause is classified as CWE-862 (Missing Authorization): Jenkins does not correctly enforce per-option permission checks on the Appearance configuration page introduced in version 2.421. An authenticated attacker with the Overall/Manage permission can submit configuration changes to Appearance options that should require a higher privilege level (e.g., Overall/Administer). The practical impact is plugin-dependent — for instance, if the Simple Theme Plugin is installed, an attacker could specify URLs for JavaScript resources loaded on every Jenkins page, potentially enabling a stored cross-site scripting (XSS) attack against other users. No public proof-of-concept exploit code has been identified (Jenkins Advisory, GitHub Advisory).
Successful exploitation allows an attacker with Overall/Manage permission to modify Appearance configuration settings they should not have access to, resulting in low confidentiality and low integrity impact with no direct availability impact. The most significant risk arises when plugins like Simple Theme Plugin are installed, as an attacker could inject malicious JavaScript URLs into every Jenkins page, leading to a stored XSS condition that could compromise other users' sessions or credentials. The scope of impact is limited to the Jenkins instance itself and does not directly enable lateral movement or remote code execution on its own (Jenkins Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the advisory date (Feedly). The vulnerability requires the attacker to already hold Overall/Manage permission and requires user interaction (UI:R), limiting its exploitability. The EPSS score is approximately 0.164–0.184%, placing it in a low percentile for near-term exploitation likelihood. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
/manage/appearance or equivalent) using the authenticated session./manage/appearance/configure) with unexpected parameter values.config.xml entries for Simple Theme Plugin) with externally hosted resource URLs not previously configured by administrators.Jenkins has released fixed versions: Jenkins 2.580 (weekly) and LTS 2.568.3, both of which ensure each Appearance configuration option is only accessible to users with the required permission. Administrators should upgrade to these versions immediately. As a short-term workaround, restrict the Overall/Manage permission to fully trusted users only, and audit installed plugins (especially Simple Theme Plugin) for unauthorized configuration changes. Monitor audit logs for unexpected Appearance configuration modifications (Jenkins Advisory).
The vulnerability was disclosed as part of a large Jenkins security advisory on September 2, 2026, covering over 30 CVEs across Jenkins core and multiple plugins. The advisory was picked up by security aggregators including AUSCERT (ESB-2026.10414), Tenable, and the OSS-Security mailing list. Community reaction has been focused primarily on the higher-severity vulnerabilities in the same advisory (e.g., the deserialization RCE CVE-2026-84645), with CVE-2026-84653 receiving less individual attention due to its lower CVSS score and prerequisite of an already-privileged account (Jenkins Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."