Missing Permission Check in Jenkins Allows Unauthorized Access to Job Parameters
CVE-2026-84656
Currently unrated
What is CVE-2026-84656?
A vulnerability exists in Jenkins where a missing permission check allows users with Item/Read permission on at least one job to gain unauthorized access to build parameter names and values of other jobs. This issue is present in Jenkins 2.579 and earlier, as well as Jenkins LTS 2.568.2 and earlier versions. Such a flaw may lead to a potential information disclosure risk, which could be exploited by attackers to retrieve sensitive build details without proper authorization.
Affected Version(s)
Jenkins 2.580
Jenkins 2.580
Jenkins 2.568.3 < 2.568.*