Junglewise Threat Intelligence

CVE-2026-84652: Jenkins session fixation via remember me cookie

CVE-2026-84652 · Severity: high · CVSS 7.3 · Published 2026-09-02

Technologies: Jenkins. Vendors: Jenkins.

Executive brief

Jenkins is an automation server used to build, test, and deploy software. A flaw in the "remember me" login feature allows attackers to pre-set a session cookie in a victim's browser; when the victim logs in via "remember me," the attacker gains unauthorized access to Jenkins and can view sensitive projects, trigger builds, or modify configurations depending on the victim's permissions.

Technical details

Jenkins fails to rotate the session identifier when a user authenticates via the "remember me" cookie mechanism. An attacker able to serve content on the same site as Jenkins (e.g., a sibling subdomain or shared domain) can inject a known session cookie into the victim's browser. When the victim later authenticates using the "remember me" feature, the pre-set session cookie remains valid, allowing the attacker to hijack the authenticated session without knowing the victim's credentials. This is a session fixation attack requiring an attacker with some control over the Jenkins hosting domain or network position to inject cookies. The attack is partially mitigated in environments with strict cookie policies, but affects Jenkins 2.579 and earlier, and LTS 2.568.2 and earlier.

Affected products

  • Jenkins Jenkins 2.579 and earlier, LTS 2.568.2 and earlier

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: advisory

References

Related threats