PT-2026-20434 · Jenkins+1 · Jenkins+1

Suman Roy

·

Published

2026-02-18

·

Updated

2026-03-20

·

CVE-2026-27100

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.550 and earlier Jenkins LTS versions 2.541.1 and earlier
Description The software allows access to information about jobs, builds, and build display names even when a user does not have permission to view them. This occurs because the software accepts Run Parameter values that reference builds inaccessible to the user submitting the build. An attacker with Item/Build and Item/Configure permission can exploit this.
Recommendations Update Jenkins to a version later than 2.550. Update Jenkins LTS to a version later than 2.541.1.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2026-05583
BIT-JENKINS-2026-27100
CVE-2026-27100
GHSA-WFHP-QGM8-5P5C

Affected Products

Jenkins
Red Os