CVE-2026-84660
Received Received - Intake

Permission Check Bypass in Jenkins Pipeline Build Step Plugin

Vulnerability report for CVE-2026-84660, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Jenkins Project

Description

A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds triggered by the `build` step to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jenkinsci build_step_plugin to 599.v4b_67ea_11b_152 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing permission check in Jenkins Pipeline: Build Step Plugin. It allows downstream builds triggered by the build step to be canceled even when the user's authentication lacks the required Item/Cancel permission on the downstream job.

Impact Analysis

This vulnerability could allow unauthorized users to cancel builds they are not permitted to, potentially disrupting CI/CD pipelines and causing unexpected downtime in Jenkins environments.

Mitigation Strategies

Update Jenkins Pipeline: Build Step Plugin to version 599.v4b_67ea_11b_152 or later to address the missing permission check issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84660. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart