Intel

AIKIDO-2026-37378

pipeline-build-step is vulnerable to Missing Authorization

Missing AuthorizationCVE-2026-84660 Published Today

43

Medium Risk

This Affects:

JAVApipeline-build-step
0.0.1 - 599
Fixed in 601
Are you affected? Scan for Free

TL;DR

Canceling a Pipeline that triggered a downstream job with the build step can cancel that downstream build without checking Item/Cancel on the downstream job. Builds running with constrained authentication can still abort downstream work they should not control. The fix requires Item/Cancel permission on the downstream job before cancellation.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and Pipelines can trigger downstream builds with the build step.

Background info

pipeline-build-step is vulnerable to Missing Authorization in versions 0.0.1 - 599.

How to fix this

Upgrade the org.jenkins-ci.plugins:pipeline-build-step library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform