Executive brief
Jenkins, a popular automation and CI/CD server used by enterprises to build and deploy applications, contains a permission bypass flaw in its Appearance configuration page. An attacker with limited admin permissions (Overall/Manage) can modify appearance settings they should not have access to, potentially defacing Jenkins or exposing configuration details to unauthorized users.
Technical details
Jenkins 2.421–2.579 and LTS 2.426.1–2.568.2 fail to enforce proper permission checks on the Appearance configuration page. The vulnerability allows attackers holding Overall/Manage permission to access and modify Appearance options beyond their intended authorization scope. This is a logic flaw in permission validation rather than an authentication bypass. The issue was fixed in Jenkins 2.580 and LTS 2.568.3. No authentication bypass is required; the attacker must already possess Overall/Manage rights.
Affected products
- Jenkins Jenkins 2.421 through 2.579, LTS 2.426.1 through 2.568.2
Timeline
- 2026-09-02: disclosed
- 2026-09-02: patched: Fixed in Jenkins 2.580 and LTS 2.568.3