
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84656 is a missing permission check vulnerability in Jenkins core (tracked as SECURITY-4006) that allows authenticated attackers to read build parameter names and values of jobs they are not authorized to access. It affects Jenkins 2.579 and earlier and LTS 2.568.2 and earlier. The vulnerability was disclosed on September 2, 2026, via the Jenkins Security Advisory. It carries a CVSS v3.1 base score of 4.3 (Medium) (Jenkins Advisory, GitHub Advisory).
The root cause is a missing authorization check (CWE-862) in an HTTP endpoint within Jenkins core. An attacker with Item/Read permission on at least one job can send a crafted request to the affected endpoint and retrieve build parameter names and values from jobs they otherwise have no access to — bypassing Jenkins' role-based access control model. No special configuration is required beyond having a low-privileged authenticated account with Item/Read on any single job. The fix in Jenkins 2.580 and LTS 2.568.3 adds the required Item/Read permission check to the affected endpoint (Jenkins Advisory).
Successful exploitation results in unauthorized disclosure of build parameter names and values from restricted jobs, which may include sensitive data such as API keys, credentials, environment-specific secrets, or deployment configuration passed as build parameters. The impact is limited to confidentiality (no integrity or availability impact), but exposed parameters could facilitate further attacks, such as credential theft or lateral movement within CI/CD pipelines (Jenkins Advisory, GitHub Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at the time of disclosure (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.178%, placing it in the 7th percentile for exploitation likelihood within 30 days. Exploitation requires a valid authenticated account with at least Item/Read permission on one job, making it non-trivially accessible but still a realistic insider or low-privilege threat (GitHub Advisory).
Upgrade Jenkins to version 2.580 (weekly) or LTS 2.568.3, which adds the required Item/Read permission check to the affected HTTP endpoint. No configuration-based workaround is available for this specific vulnerability; upgrading is the only remediation. As a defense-in-depth measure, administrators should audit and restrict which users have authenticated access to Jenkins and enforce least-privilege role assignments using the Role Strategy Plugin or similar (Jenkins Advisory).
The vulnerability was reported through the Jenkins Bug Bounty Program sponsored by the European Commission, reflecting the project's structured approach to security research. The September 2, 2026 advisory addressed a large batch of vulnerabilities across Jenkins core and multiple plugins, with higher-severity issues (such as RCE via deserialization) drawing more community attention than this medium-severity information disclosure finding. No notable independent researcher commentary or significant social media discussion specific to CVE-2026-84656 has been identified (Jenkins Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."