Intel

AIKIDO-2026-729304

pipeline-build-step is vulnerable to Missing Authorization

Missing AuthorizationCVE-2026-84661 Published Today

43

Medium Risk

This Affects:

JAVApipeline-build-step
0.0.1 - 599
Fixed in 601
Are you affected? Scan for Free

TL;DR

The waitForBuild step with propagateAbort=true can cancel downstream builds without checking Item/Cancel permission on the downstream job. This allows constrained build authentication to abort downstream jobs it should not be allowed to cancel. The fix enforces Item/Cancel permission before cancellation in this code path.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and Pipelines use waitForBuild with propagateAbort=true for downstream builds.

Background info

pipeline-build-step is vulnerable to Missing Authorization in versions 0.0.1 - 599.

How to fix this

Upgrade the org.jenkins-ci.plugins:pipeline-build-step library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform