Access Control Vulnerability in Jenkins by CloudBees
CVE-2026-27100
4.3MEDIUM
What is CVE-2026-27100?
An access control vulnerability in Jenkins allows users with limited permissions to access run parameters tied to jobs they are not authorized to see. Specifically, it permits users with Item/Build and Item/Configure permissions to discern the existence of jobs and builds, along with sensitive information such as display names of specific builds. This risk highlights the need for enhanced access controls to protect against unauthorized information disclosure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins 2.551
Jenkins 2.551
Jenkins 2.541.2 < 2.541.*
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved