SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84657

MEDIUM · CVSS 4.2 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Jenkins versions 2.579 and earlier, as well as LTS 2.568.2 and earlier, are vulnerable due to a flaw in the build CLI command that fails to enforce proper permission checks when using the -s flag to cancel builds. This oversight allows users with Item/Build permission to cancel builds initiated by other users, potentially disrupting workflows and leading to unauthorized interference. Organizations using affected Jenkins versions should prioritize this vulnerability to mitigate risks associated with unauthorized build cancellations.

CVE
CVE-2026-84657
Severity
MEDIUM
CVSS
4.2
EPSS
0.18%
Jenkins

Original NVD Description

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users.

Related CVEs

Other vulnerabilities affecting the same vendor(s)