Jenkins Pipeline: Build Step Plugin Vulnerability Affects Multiple Versions
CVE-2026-84660

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
2 September 2026

What is CVE-2026-84660?

The Jenkins Pipeline: Build Step Plugin has a flaw due to a missing permission check, allowing downstream builds to be canceled even if the triggering user lacks sufficient permissions on the downstream job. This oversight can pose a security risk, as it may lead to unauthorized actions within Jenkins workflows, undermining the integrity of the build process.

Affected Version(s)

Jenkins Pipeline: Build Step Plugin 0 <= 599.v4b_67ea_11b_152

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.