PatchSiren cyber security CVE debrief
CVE-2026-84657 Jenkins Project CVE debrief
The CVE-2026-84657 vulnerability affects Jenkins versions 2.579 and earlier, LTS 2.568.2 and earlier. This issue is related to the build CLI command, which does not properly check Item/Cancel permissions when using the -s flag to cancel a build triggered to wait for completion. As a result, attackers with Item/Build permission can cancel builds started by other users. Jenkins administrators and users with Item/Build permissions should be aware of this vulnerability and take steps to mitigate it by applying vendor patches or restricting permissions. The vulnerability has a medium severity level, with a CVSS score of 4.2.
- Vendor
- Jenkins Project
- Product
- Jenkins
- CVSS
- MEDIUM 4.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-03
Who should care
Jenkins administrators and users with Item/Build permissions should be aware of this vulnerability and take steps to mitigate it. They should apply vendor patches or restrict permissions to prevent attackers from canceling builds started by other users. Additionally, security teams and platform operators should review the vulnerability and its potential impact on their environments, and consider implementing compensating controls for exposed systems while remediation is scheduled and verified. Monitoring and detection capabilities should also be reviewed to ensure that potential exploitation attempts are identified and responded to promptly. Asset inventory and change management processes should be updated to reflect the vulnerability and associated remediation efforts. This vulnerability may require additional review and verification to ensure that affected systems are properly patched or mitigated, and that there is no unauthorized access or exploitation. Therefore, it is essential to assign an owner for follow-up and track exceptions, retest remediated assets, and close the item only after evidence is documented. The vulnerability management process should be updated to include this vulnerability and ensure that it is addressed in a timely manner. The security team should also review the vulnerability and provide guidance on the necessary steps to mitigate it. The affected product or component is Jenkins, and the vulnerability class is related to permission checks in the build CLI command. The likely operational impact is that attackers with Item/Build permission can cancel builds started by other users, which could lead to disruptions in the build process and potential security issues. The source-confidence limits are medium, as the vulnerability is based on official CVE and NVD sources. The review context is that the vulnerability has a medium severity level and requires prompt attention from Jenkins administrators and users with Item/Build permissions. The defensive impact is that administrators should apply vendor patches or restrict permissions to prevent exploitation. The source-grounded technical framing is that the vulnerability is related to the lack
Technical summary
The Jenkins build CLI command does not check Item/Cancel permissions when using the -s flag to cancel a build triggered to wait for completion. This allows attackers with Item/Build permission to cancel builds started by other users in Jenkins versions 2.579 and earlier, LTS 2.568.2 and earlier. The vulnerability has a medium severity level, with a CVSS score of 4.2. To mitigate this issue, administrators should apply vendor patches to update Jenkins to version 2.580 or later, LTS 2.568.3 or later, and restrict Item/Build and Item/Cancel permissions to prevent exploitation.
Defensive priority
Medium priority for Jenkins administrators; verify and apply vendor patches promptly.
Recommended defensive actions
- Apply the vendor patch to update Jenkins to version 2.580 or later, LTS 2.568.3 or later.
- Restrict Item/Build and Item/Cancel permissions to prevent exploitation.
- Monitor Jenkins instance for unauthorized build cancellations.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
Evidence from official CVE and NVD sources indicates a medium-severity vulnerability in Jenkins versions 2.579 and earlier, LTS 2.568.2 and earlier. The build CLI command does not properly check Item/Cancel permissions when using the -s flag, allowing attackers with Item/Build permission to cancel builds started by other users.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-84657 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-84657
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-84657 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84657
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.jenkins.io/security/advisory/2026-09-02/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.