CVE-2026-53438: Jenkins: Missing permission check allows unauthorized cancellation of queue items
(updated )
A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission, but lacking Item/Read permission, to cancel queue items they do not have permission to view.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-53438 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →