
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84655 is an injection vulnerability (tracked as SECURITY-3879) in Jenkins's REST API that allows authenticated attackers with low privileges to inject arbitrary fields into JSON and Python API responses. It affects Jenkins 2.579 and earlier, and LTS 2.568.2 and earlier. The vulnerability was disclosed on September 2, 2026, as part of a broader Jenkins security advisory. It carries a CVSS v3.1 base score of 4.3 (Medium) (Jenkins Advisory, GitHub Advisory).
The root cause is improper encoding or escaping of output (CWE-116): Jenkins does not escape map keys when serializing objects as JSON or Python-format responses through its REST API. An attacker who can control map property names — for example, by naming a Jenkins resource (such as a job, parameter, or environment variable) with specially crafted strings — can cause those unescaped keys to be interpreted as additional fields in the serialized API response, effectively injecting arbitrary content. Exploitation requires network access and a low-privileged authenticated account; no user interaction is needed. No public proof-of-concept code has been identified (Jenkins Advisory, GitHub Advisory).
Successful exploitation allows a low-privileged authenticated attacker to tamper with the integrity of JSON and Python REST API responses consumed by Jenkins clients, scripts, or integrations. The primary impact is data integrity — injected fields could mislead downstream consumers of the API, potentially causing incorrect automation decisions or masking the true state of Jenkins resources. There is no direct confidentiality or availability impact, and no evidence of lateral movement potential from this vulnerability alone (Jenkins Advisory, GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the advisory date (GitHub Advisory). The EPSS score is approximately 0.19% (9th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
","injected_key":"injected_value","x as a map key).GET /job/<crafted-job-name>/api/json)./api/json or /api/python) to resources with unusual or specially crafted names containing JSON-significant characters (", :, {, }, ,).Jenkins has released fixed versions that escape map keys when serializing objects as JSON and Python through the REST API: Jenkins 2.580 (weekly) and LTS 2.568.3. Administrators should upgrade to one of these versions as the primary remediation. No configuration-based workaround is documented for this specific vulnerability; upgrading is the recommended and only reliable fix. Additionally, implementing WAF rules to detect anomalous characters in REST API request paths and enforcing strict schema validation on API consumers can reduce risk in the interim (Jenkins Advisory).
The vulnerability was disclosed as part of a large Jenkins security advisory on September 2, 2026, covering over 30 CVEs across Jenkins core and plugins. The advisory received coverage from security aggregators including AusCERT (ESB-2026.10414), Tenable, and OSS-Sec mailing lists. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-84655 has been identified, likely due to its moderate severity relative to higher-impact CVEs in the same advisory (Jenkins Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."