Junglewise Threat Intelligence

CVE-2026-84656: Jenkins missing permission check on build parameters

CVE-2026-84656 · Severity: medium · CVSS 4.3 · Published 2026-09-02

Technologies: Jenkins. Vendors: Jenkins.

Executive brief

Jenkins, a widely-used automation and CI/CD server, contains a permission bypass flaw that allows attackers with limited access (Item/Read on one job) to read sensitive build parameter names and values from jobs they should not have access to. Build parameters often contain secrets such as API keys, passwords, and deployment credentials, making this exposure a risk to operational security and compliance.

Technical details

Jenkins 2.579 and earlier (LTS 2.568.2 and earlier) fails to properly validate permissions when exposing build parameter metadata. An attacker with Item/Read permission on at least one job can leverage this missing permission check to enumerate and read parameter names and values from jobs outside their authorization scope. The vulnerability is network-accessible and does not require authentication beyond the minimum Item/Read permission already held on one accessible job. Exploitation could expose API keys, passwords, and other sensitive configuration data stored in build parameters. Jenkins 2.580 and LTS 2.568.3 include a fix restricting parameter access based on proper job-level authorization checks.

Affected products

  • Jenkins Jenkins 2.579 and earlier, LTS 2.568.2 and earlier

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: patched: Jenkins 2.580, LTS 2.568.3

References

Related threats