PT-2026-84784 · Jenkins · Jenkins Pipeline: Build Step Plugin

CVE-2026-84661

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b 67ea 11b 152 and earlier causes downstream builds awaited by the waitForBuild step when the propagateAbort parameter is used to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84661

Affected Products

Jenkins Pipeline: Build Step Plugin