Vulnerability Description
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML document, allowing attackers with Agent/Configure permission on one agent to take over a different agent, gaining control of its configuration and obtaining access to its inbound agent secret and environment variables.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Jenkins | < 2.568.3 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-84651?
CVE-2026-84651 is a vulnerability with a CVSS score of 6.3 (MEDIUM). In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by sp...
How severe is CVE-2026-84651?
CVE-2026-84651 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-84651?
Check the references section above for vendor advisories and patch information. Affected products include: Jenkins Jenkins.