Missing Permission Check in Jenkins Allows Unauthorized Access to Job Parameters
CVE-2026-84656

Currently unrated

Key Information:

Vendor

Jenkins

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84656?

A vulnerability exists in Jenkins where a missing permission check allows users with Item/Read permission on at least one job to gain unauthorized access to build parameter names and values of other jobs. This issue is present in Jenkins 2.579 and earlier, as well as Jenkins LTS 2.568.2 and earlier versions. Such a flaw may lead to a potential information disclosure risk, which could be exploited by attackers to retrieve sensitive build details without proper authorization.

Affected Version(s)

Jenkins 2.580

Jenkins 2.580

Jenkins 2.568.3 < 2.568.*

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.