LOWVulnerability

CVE-2026-84653

Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.

Properties

severity
LOW
score
3.5
epss_score
0.00184
cve_id
CVE-2026-84653
signal_observed_at
2026-09-15T21:12:51+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
published_at
2026-09-02T16:17:29.983
last_modified
2026-09-15T18:15:37.527
epss_percentile
0.08145

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (2)

[Product]
[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84653 — Ninja Signal Threat Intelligence | Ninja Signal