CVE-2026-84660: Jenkins/Jenkins Pipeline: Build Step Plugin vulnerability

Published Sep 2, 2026
·
Updated

A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b67ea11b152 and earlier causes downstream builds triggered by the build step to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job.

Affected Software

1 affected component
jenkins/Jenkins Pipeline: Build Step Plugin<=599.v4b_67ea_11b_152

Event History

Sep 2, 2026
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
Description
Data Sourced
via NVD·04:17 PM
Description

Frequently Asked Questions

1

Who is affected by this issue?

Jenkins instances using Pipeline: Build Step Plugin version 599.v4b_67ea_11b_152 or earlier are affected when Pipeline jobs use the build step to trigger downstream builds.

2

What permissions does an attacker need to exploit this?

The relevant authentication must be able to trigger a downstream build through the build step. The issue allows that downstream build to be canceled even if that authentication does not have Item/Cancel permission on the downstream job.

3

What is the impact of exploitation?

An unauthorized user or process can cause downstream builds triggered by the build step to be canceled. This can disrupt job execution despite the absence of Item/Cancel permission on the affected downstream job.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203