CVE-2026-27100
ADVISORY - githubSummary
Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing attackers with Item/Build and Item/Configure permission to obtain information about the existence of jobs, the existence of builds, and if a specified build exists, its display name.
EPSS Score: 0.00027 (0.075)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Exposure of Sensitive Information to an Unauthorized Actor
ADVISORY - github
Exposure of Sensitive Information to an Unauthorized Actor
ADVISORY - redhat
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-27100
EXPLOITABILITY SCORE
2.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
4.3mediumGitHub
CREATED
UPDATED
ADVISORY IDGHSA-wfhp-qgm8-5p5c
EXPLOITABILITY SCORE
2.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
4.3mediumBitnami
CREATED
UPDATED
ADVISORY ID
BIT-jenkins-2026-27100
EXPLOITABILITY SCORE
2.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
4.3mediumRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2026-27100
EXPLOITABILITY SCORE
2.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)