CVE-2026-84648
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 02, 2026
Vendor
unknown
Description
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes.