SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84656

MEDIUM · CVSS 4.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Jenkins versions 2.579 and earlier, as well as LTS 2.568.2 and earlier, are vulnerable due to a missing permission check that allows users with Item/Read permission on at least one job to access sensitive build parameter names and values from jobs they should not have access to. This vulnerability could lead to unauthorized information disclosure, potentially exposing sensitive data or configurations. Organizations using affected Jenkins versions should prioritize remediation to safeguard their CI/CD pipelines and sensitive information.

CVE
CVE-2026-84656
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%
Jenkins

Original NVD Description

A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to.

Related CVEs

Other vulnerabilities affecting the same vendor(s)