Vulnerability Details CVE-2026-84646
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 15.4%
CVSS Severity
CVSS v3 Score 4.3