MEDIUMVulnerability

CVE-2026-84656

A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to.

Properties

severity
MEDIUM
score
4.3
epss_score
0.00178
cve_id
CVE-2026-84656
signal_observed_at
2026-09-15T21:12:51+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
published_at
2026-09-02T16:17:30.273
last_modified
2026-09-15T18:06:43.853
epss_percentile
0.07534

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (2)

[Product]
[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84656 — Ninja Signal Threat Intelligence | Ninja Signal