MEDIUMVulnerability

CVE-2026-84655

Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses.

Properties

severity
MEDIUM
score
4.3
epss_score
0.00192
cve_id
CVE-2026-84655
signal_observed_at
2026-09-15T21:12:51+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
published_at
2026-09-02T16:17:30.177
last_modified
2026-09-15T18:07:05.090
epss_percentile
0.09066

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Encoding or Escaping of Output

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (2)

[Product]
[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84655 — Ninja Signal Threat Intelligence | Ninja Signal