Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-09-02T17:16:57.165Z
Reserved: 2026-09-01T21:55:27.034Z
Link: CVE-2026-84657
Updated: 2026-09-02T17:16:50.172Z
Status : Received
Published: 2026-09-02T16:17:30.373
Modified: 2026-09-02T18:21:31.733
Link: CVE-2026-84657
No data.
OpenCVE Enrichment
No data.
-
CWE-862
Missing Authorization