SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84660

MEDIUM · CVSS 5.4 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A missing permission check in the Jenkins Pipeline: Build Step Plugin allows unauthorized users to cancel downstream builds triggered by the `build` step, even if they lack the necessary Item/Cancel permission on those jobs. This vulnerability could lead to disruptions in the build process and potential denial of service for affected projects. Jenkins administrators and users of the affected plugin versions should prioritize applying updates to mitigate this risk.

CVE
CVE-2026-84660
Severity
MEDIUM
CVSS
5.4
EPSS
0.23%
Jenkins

Original NVD Description

A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds triggered by the `build` step to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job.