CVE-2026-84652
Summary
| CVE | CVE-2026-84652 |
| State | PUBLISHED |
| Assigner | jenkins |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-02 16:17:29 UTC |
| Updated | 2026-09-02 16:17:29 UTC |
| Description | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which after the victim authenticates via the "remember me" cookie, grants the attacker access to Jenkins as that user. |
Vendor Declared Affected Products
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.