Impact
The vulnerability arises because Jenkins fails to enforce permission checks on the Appearance configuration page. Users with Overall/Manage rights can modify appearance settings that should be restricted, allowing them to change configuration options without proper authorization. This is a missing authorization flaw (CWE-862).
Affected Systems
Affected systems are Jenkins servers supplied by the Jenkins Project. The flaw applies to core releases 2.421 through 2.579 inclusive, and the long‑term support releases 2.426.1 through 2.568.2 inclusive.
Risk and Exploitability
The CVSS score of 3.5 indicates moderate severity, primarily because the bug does not allow remote code execution or direct privilege escalation; it requires an attacker to already possess Overall/Manage permission. The EPSS score of <1% and the absence from the CISA KEV catalog suggest a low probability of public exploitation. While unauthorized changes to appearance settings could affect the user interface or plugin behavior, the overall risk remains limited unless the compromised account also has other high‑privilege permissions that could be abused indirectly.
OpenCVE Enrichment