GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins: Overall/Manage holders can change Appearance configuration reserved for administrators

CVSS 3.5CVE-2026-84653Control plane, storage & DevOpscurated

Impact

The Appearance configuration page does not check permissions correctly, so users holding Overall/Manage can change options that are supposed to require Overall/Administer. Overall/Manage exists precisely so build operators can run the controller day to day without being administrators, and this erodes that line. The record does not enumerate which options become reachable, so judge it on what it is: a privilege-boundary defect on the controller, not a takeover. Scored 3.5, requiring an already-privileged account plus user interaction, so this is a housekeeping item rather than a reason to touch a maintenance window.

Who can reach it

A Jenkins user who already holds Overall/Manage but not Overall/Administer, working through the controller web UI. The vendor vector marks user interaction as required (UI:R), so it is not a fully self-contained action.

What to do

Affected ranges are 2.421 through 2.579 and LTS 2.426.1 through 2.568.2; the record does not name the fixed release, so take it from the Jenkins advisory of 2026-09-02 (SECURITY-3981). Upgrading the controller means restarting it and losing in-flight builds, which is the whole cost here. Given the severity and the fact that the attacker already needs a Manage-level account, fold this into your next scheduled controller upgrade rather than scheduling one for it, and in the meantime review who actually holds Overall/Manage.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.