{"id":"CVE-2026-84657","title":"In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permissi…","summary":"In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permissi…","severity":"medium","cvss":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-862"],"vendor":"jenkins","product":"jenkins","affected":["jenkins <= 2.568.2","jenkins <= 2.579"],"published":"2026-09-02","updated":"2026-09-15","sourceUpdated":"2026-09-15T18:05:47.627","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84657","references":[{"url":"https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-4015","label":"jenkinsci-cert@googlegroups.com"}],"tags":["nvd"],"epss":0.00185,"epssPercentile":0.08302,"ingestedAt":"2026-09-15T18:41:59.125Z","slug":"CVE-2026-84657","body":"## Overview\n\nIn Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users.\n\n## Affected\n\n- `jenkins <= 2.568.2`\n- `jenkins <= 2.579`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}