Description
Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.
Published: 2026-09-02
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from missing permission checks on Jenkins’ Appearance configuration page. Attackers who possess Overall/Manage rights can change configuration options that should be restricted, potentially altering the UI or plugin behavior in ways that were not intended. This flaw enables unauthorized modification of Jenkins settings, which can lead to information disclosure or additional privilege escalation if the altered settings expose sensitive data or weaken security controls.

Affected Systems

Affected systems include the Jenkins Project’s Jenkins server. The flaw impacts versions 2.421 through 2.579 (inclusive) and 2.426.1 through 2.568.2 (inclusive) within the LTS series.

Risk and Exploitability

The CVSS score is not provided, and EPSS data is unavailable, so precise quantitative risk is unknown. The flaw is listed as not included in CISA’s KEV catalog, indicating no confirmed public exploits at the time of this analysis. The attack vector requires an attacker to already have Overall/Manage permission, which could be acquired through another compromise or misconfiguration. Since the privilege escalation allows modification of Jenkins configuration, the potential impact is significant for environments where Jenkins settings control critical build pipelines or infrastructure. However, the lack of an external exploit and the prerequisite permission suggest a moderate to high risk contingent on the threat model.

Generated by OpenCVE AI on September 3, 2026 at 12:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Jenkins to the latest released version that includes the fix for the permission check on the Appearance page.
  • Limit Overall/Manage users to the minimum necessary privileges and regularly review user roles to prevent over‑privileged accounts.
  • Enable audit logging for configuration changes and monitor for unauthorized modifications to the Appearance settings.

Generated by OpenCVE AI on September 3, 2026 at 12:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins
Vendors & Products Jenkins Project
Jenkins Project jenkins

Thu, 03 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Missing Permission Checks on Jenkins Appearance Page Allow Unauthorized Configuration Modification
Weaknesses CWE-284

Wed, 02 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to. Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.
References

Subscriptions

Jenkins Project Jenkins
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-02T16:04:31.501Z

Reserved: 2026-09-01T21:55:27.033Z

Link: CVE-2026-84653

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T16:17:29.983

Modified: 2026-09-03T17:13:16.490

Link: CVE-2026-84653

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T13:30:04Z

Weaknesses