CVE-2026-84657
Last modified
CVE-2026-84657 is a medium-severity vulnerability rated 4.2/10 on the CVSS scale. In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Jenkins Project | Jenkins | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-84657?
How severe is CVE-2026-84657?
How do I fix CVE-2026-84657?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-84651In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the R…6.3
- CVE-2026-84652In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenki…7.3
- CVE-2026-84653Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 th…3.5
- CVE-2026-84654In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093…5.4
- CVE-2026-84655Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not …4.3
- CVE-2026-84656A missing permission check in Jenkins 2.579 and earlier, LTS…4.3
- CVE-2026-84658Jenkins Script Security Plugin 1412.v7737b_3405f86 and earli…4.3
- CVE-2026-84659Jenkins Script Security Plugin 1412.v7737b_3405f86 and earli…4.3
- CVE-2026-8466Allocation of Resources Without Limits or Throttling vulnera…8.2
- CVE-2026-84660A missing permission check in Jenkins Pipeline: Build Step P…5.4
- CVE-2026-84661A missing permission check in Jenkins Pipeline: Build Step P…5.4
- CVE-2026-84662Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allow…4.3
Are you affected by CVE-2026-84657?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
