Junglewise Threat Intelligence

CVE-2026-53438: Jenkins missing permission check in queue item cancellation

CVE-2026-53438 · Severity: medium · CVSS 4.3 · Published 2026-06-10

Vendors: Jenkins Project.

Executive brief

Jenkins is an open-source automation server widely used to orchestrate build pipelines and job execution. This vulnerability allows users with limited permissions (able to cancel jobs but not read them) to cancel queued job executions they should not have visibility into. An attacker exploiting this flaw could disrupt job execution, interfere with CI/CD workflows, and potentially mask their activity or introduce build delays without proper audit trail controls.

Technical details

This is a missing authorization vulnerability (CWE-862) in an HTTP endpoint that handles queue item cancellation. The root cause is an incomplete fix of SECURITY-2278 from June 2021, where the endpoint was not updated to enforce Item/Read permission checks alongside Item/Cancel checks. An attacker with Item/Cancel permission but lacking Item/Read permission can directly invoke this endpoint to cancel queue items they do not have permission to view or access. The vulnerability is network-accessible and requires only that the attacker possess the Item/Cancel permission (which may be granted to users in limited roles). No user interaction is required. Jenkins 2.568 and LTS 2.555.3 fix this by adding the missing Item/Read permission check in the affected endpoint.

Affected products

  • Jenkins Project Jenkins 2.567 and earlier; LTS 2.555.2 and earlier

Timeline

  • 2026-06-10: disclosed: Published in Jenkins Security Advisory 2026-06-10
  • 2026-06-10: patched: Jenkins 2.568 and LTS 2.555.3 released with fixes

References