github.com
https://github.com/jenkinsci/jenkins CVE-2026-27100
MEDIUM
Jenkins has a build information disclosure vulnerability through Run Parameter
Record summary
CVE-2026-27100 has a selected CVSS score of 4.3 (medium).
Description
Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing attackers with Item/Build and Item/Configure permission to obtain information about the existence of jobs, the existence of builds, and if a specified build exists, its display name.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 18, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | 2.551 to < * | unaffected |
| 2.541.2 to < 2.541.* | unaffected | ||
org.jenkins-ci.main:jenkins-coreBrowse Maven / org.jenkins-ci.main:jenkins-core | GitHub Advisory | 2.542 to < 2.551 · Fixed in 2.551 | affected |
| Before 2.541.2 · Fixed in 2.541.2 | affected |
References
6github.com
https://github.com/jenkinsci/jenkins/commit/f92eadb5813f04ca27439455e2573c3171e93a45 github.com
https://github.com/jenkinsci/jenkins/releases/tag/jenkins-2.541.2 github.com
https://github.com/jenkinsci/jenkins/releases/tag/jenkins-2.551 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-27100 Jenkins Security Advisory 2026-02-18Vendor advisory
https://www.jenkins.io/security/advisory/2026-02-18