Security Advisory

CVE-2026-84653

3.5
LOW

Vulnerability Description

Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.
Published Date September 2, 2026
Official Source NIST NVD Advisory