Permission Check Flaw in Jenkins Affects User Data Access
CVE-2025-59474

Currently unrated

Key Information:

Vendor

Jenkins

Status
Vendor
CVE Published:
17 September 2025

What is CVE-2025-59474?

A significant vulnerability has been identified in Jenkins that fails to enforce proper permission checks for users lacking Overall/Read permissions. Specifically, those who do not possess the necessary permissions can exploit this flaw to access and enumerate agent names through the sidepanel executors widget, thereby exposing sensitive system information that should be restricted. This issue affects Jenkins versions up to 2.527 and LTS 2.516.2 or earlier, raising serious concerns about unauthorized data visibility and potential security breaches.

Affected Version(s)

Jenkins 0

Jenkins 0 < 2.387

Jenkins 2.516.3 < 2.516.*

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59474 : Permission Check Flaw in Jenkins Affects User Data Access