Intel

AIKIDO-2026-923981

jenkins-core is vulnerable to Missing Authorization

Missing AuthorizationCVE-2026-84656 Published Yesterday

43

Medium Risk

This Affects:

JAVAjenkins-core
0.0.1 - 2.568.2
Fixed in 2.568.3
2.569 - 2.579
Fixed in 2.580
Are you affected? Scan for Free

TL;DR

An HTTP endpoint omits an Item/Read permission check for build parameter data. A user with Item/Read permission on one job can read build parameter names and values from jobs they should not access. The fix adds the missing Item/Read permission check in the affected endpoint.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and users with Item/Read on at least one job can access the affected HTTP endpoint.

Background info

jenkins-core is vulnerable to Missing Authorization in versions 0.0.1 - 2.568.2 and 2.569 - 2.579.

How to fix this

Upgrade the org.jenkins-ci.main:jenkins-core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform