---
id: CVE-2025-64132
title: >-
  Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform
  permission checks in multiple MCP tools, allowing attackers to trigger builds
  and obtain information about job and cloud configuration they should not be
  able to …
summary: >-
  Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform
  permission checks in multiple MCP tools, allowing attackers to trigger builds
  and obtain information about job and cloud configuration they should not be
  able to …
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-862
vendor: jenkins
product: mcp_server
affected:
  - mcp_server < 0.86.v7d3355e6a_a_18
patched:
  - mcp_server 0.86.v7d3355e6a_a_18
published: '2025-10-29'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64132'
references:
  - url: 'https://www.jenkins.io/security/advisory/2025-10-29/#SECURITY-3622'
    label: jenkinsci-cert@googlegroups.com
  - url: 'http://www.openwall.com/lists/oss-security/2025/10/29/2'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00262
epssPercentile: 0.1647
ingestedAt: '2026-10-08T11:31:27.674Z'
---

## Overview

Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and obtain information about job and cloud configuration they should not be able to access.

## Affected

- `mcp_server < 0.86.v7d3355e6a_a_18`

## Remediation

Upgrade past the affected range:

- `mcp_server 0.86.v7d3355e6a_a_18`
