cbcvebase.
CVE-2026-57280
published 2026-06-24

CVE-2026-57280: Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in…

PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.38%
30.6th percentile
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsactive_directory
jenkinsactive_directory_plugin
jenkinsassembla
jenkinsassembla_plugin
jenkinsbitbucket_push_and_pull_request
jenkinsbitbucket_push_and_pull_request_plugin
jenkinscontrast_continuous_application_security
jenkinscontrast_continuous_application_security_plugin
jenkinsec2_fleet
jenkinsec2_fleet_plugin
jenkinsexternal_workspace_manager
jenkinsexternal_workspace_manager_plugin
jenkinsfitnesse
jenkinsfitnesse_plugin
jenkinsgit_client
jenkinsgit_client_plugin
jenkinsgit_parameter
jenkinsgit_parameter_plugin
jenkinsgitee
jenkinsgitee_plugin
jenkinsgithub_branch_source
jenkinsgithub_branch_source_plugin
jenkinsgroovy
jenkinsgroovy_plugin
jenkinsjenkins

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.