cbcvebase.
CVE-2026-57300
published 2026-06-24

CVE-2026-57300: A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay…

PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.18%
7.5th percentile
A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsactive_directory
jenkinsactive_directory_plugin
jenkinsassembla
jenkinsassembla_plugin
jenkinsbitbucket_push_and_pull_request
jenkinsbitbucket_push_and_pull_request_plugin
jenkinscontrast_continuous_application_security
jenkinscontrast_continuous_application_security_plugin
jenkinsec2_fleet
jenkinsec2_fleet_plugin
jenkinsexternal_workspace_manager
jenkinsexternal_workspace_manager_plugin
jenkinsfitnesse
jenkinsfitnesse_plugin
jenkinsgit_client
jenkinsgit_client_plugin
jenkinsgit_parameter
jenkinsgit_parameter_plugin
jenkinsgitee
jenkinsgitee_plugin
jenkinsgithub_branch_source
jenkinsgithub_branch_source_plugin
jenkinsgroovy
jenkinsgroovy_plugin
jenkinsjenkins_controller_by_owasp_zap
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.