HIGHVulnerability

CVE-2026-84652

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which after the victim authenticates via the "remember me" cookie, grants the attacker access to Jenkins as that user.

Properties

severity
HIGH
score
7.3
epss_score
0.00471
cve_id
CVE-2026-84652
signal_observed_at
2026-09-15T21:12:51+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
published_at
2026-09-02T16:17:29.893
last_modified
2026-09-11T21:09:18.967
epss_percentile
0.39489

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Session Fixation

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (2)

[Product]
[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84652 — Ninja Signal Threat Intelligence | Ninja Signal