Jenkins Pipeline Build Step Plugin Missing Permission Check
CVE-2026-84660 Published on September 2, 2026
A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds triggered by the `build` step to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job.
Vulnerability Analysis
CVE-2026-84660 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-84660 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-84660
Want to know whenever a new CVE is published for Jenkins? stack.watch will email you.
Affected Versions
Jenkins Project Jenkins Pipeline: Build Step Plugin:- Before and including 599.v4b_67ea_11b_152 is affected.