Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wfhp-qgm8-5p5c | Jenkins has a build information disclosure vulnerability through Run Parameter |
Fri, 20 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins jenkins |
|
| CPEs | cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* |
|
| Vendors & Products |
Jenkins
Jenkins jenkins |
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins Project
Jenkins Project jenkins |
|
| Vendors & Products |
Jenkins Project
Jenkins Project jenkins |
Thu, 19 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | org.jenkins-ci.main/jenkins-core: Jenkins: Information disclosure via unauthorized access to build parameters | |
| Weaknesses | CWE-551 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 18 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics |
cvssV3_1
|
Wed, 18 Feb 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing attackers with Item/Build and Item/Configure permission to obtain information about the existence of jobs, the existence of builds, and if a specified build exists, its display name. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-02-18T14:53:33.264Z
Reserved: 2026-02-17T16:48:49.373Z
Link: CVE-2026-27100
Updated: 2026-02-18T14:52:48.220Z
Status : Analyzed
Published: 2026-02-18T15:18:43.967
Modified: 2026-02-20T20:53:16.173
Link: CVE-2026-27100
OpenCVE Enrichment
Updated: 2026-04-17T18:45:25Z
Github GHSA