Insecure Build Command in Jenkins Affects User Permissions
CVE-2026-84657

Currently unrated

Key Information:

Vendor

Jenkins

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84657?

A vulnerability in Jenkins allows users with Item/Build permission to cancel builds initiated by other users, due to the lack of permission verification in the build CLI command when utilizing the -s flag. This oversight affects versions 2.579 and earlier, as well as LTS 2.568.2 and earlier. Attackers can exploit this vulnerability to disrupt ongoing builds, potentially impacting deployment processes and project timelines.

Affected Version(s)

Jenkins 2.580

Jenkins 2.580

Jenkins 2.568.3 < 2.568.*

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.