Missing Permission Check in Jenkins Pipeline Plugin Affects Build Processes
CVE-2026-84661

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
2 September 2026

What is CVE-2026-84661?

A vulnerability has been identified in the Jenkins Pipeline: Build Step Plugin, where a missing permission check may lead to unintended cancellation of downstream builds. This issue arises specifically when the waitForBuild step is utilized alongside the propagateAbort parameter. If the authentication for a build does not possess the required Item/Cancel permission for the downstream job, the build can still be unjustly canceled. This flaw highlights the importance of stringent permission checks to maintain the integrity of build processes within Jenkins.

Affected Version(s)

Jenkins Pipeline: Build Step Plugin 0 <= 599.v4b_67ea_11b_152

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.