Junglewise Threat Intelligence

CVE-2026-84645: Jenkins deserialization RCE in config.xml handling

CVE-2026-84645 · Severity: high · CVSS 8.8 · Published 2026-09-02

Technologies: Jenkins. Vendors: Jenkins.

Executive brief

Jenkins, a widely-used automation and CI/CD server, improperly deserializes specially crafted configuration XML files, allowing attackers to bypass security protections and gain access to the Script Console for remote code execution. An attacker with sufficient permissions can craft malicious configuration documents that execute arbitrary code on the Jenkins server.

Technical details

Jenkins uses XStream for deserialization of configuration and build data stored in XML format. The vulnerability exists in the deserialization filter logic which failed to prevent objects marked as PersistenceRoot (types storing configuration in independent top-level files) from appearing as nested field values in user-submitted config.xml documents. When deserialized, these objects can be accessed and handled as HTTP requests via the Stapler web framework, which uses reflective access to matching code elements. A crafted combination of such objects allows attackers with Overall/Read permission to gain access to the Script Console, resulting in remote code execution. The issue was fixed in Jenkins 2.580 and LTS 2.568.3 by preventing PersistenceRoot-marked types from being deserialized as nested field values.

Affected products

  • Jenkins Jenkins 2.579 and earlier, LTS 2.568.2 and earlier

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: patched: Jenkins 2.580, LTS 2.568.3

References

Related threats