Executive brief
Jenkins Pipeline: Build Step Plugin is used to trigger downstream build jobs in CI/CD pipelines. A missing permission check allows downstream builds to be canceled even when the triggering user lacks permission to cancel those jobs, enabling unauthorized disruption of build workflows.
Technical details
The vulnerability is a missing authorization check (CWE-862) in Jenkins Pipeline: Build Step Plugin version 599.v4b_67ea_11b_152 and earlier. When the `build` step is used to trigger downstream builds, the plugin fails to verify that the authenticated user has the Item/Cancel permission on the downstream job before processing cancellation requests. This allows an attacker with network access to the Jenkins instance and ability to create or modify pipeline jobs to cancel downstream builds they are not authorized to manage. The plugin was patched in a later version to enforce the required permission checks.
Affected products
- Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier
Timeline
- 2026-09-02: disclosed
- 2026-09-02: advisory: Jenkins Security Advisory 2026-09-02