cbcvebase.
CVE-2026-57303
published 2026-06-24

CVE-2026-57303: Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the…

PriorityP344high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
EPSS
0.22%
12.9th percentile
Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsactive_directory
jenkinsactive_directory_plugin
jenkinsassembla<= 1.4
jenkinsassembla
jenkinsassembla_plugin
jenkinsbitbucket_push_and_pull_request
jenkinsbitbucket_push_and_pull_request_plugin
jenkinscontrast_continuous_application_security
jenkinscontrast_continuous_application_security_plugin
jenkinsec2_fleet
jenkinsec2_fleet_plugin
jenkinsexternal_workspace_manager
jenkinsexternal_workspace_manager_plugin
jenkinsfitnesse
jenkinsfitnesse_plugin
jenkinsgit_client
jenkinsgit_client_plugin
jenkinsgit_parameter
jenkinsgit_parameter_plugin
jenkinsgitee
jenkinsgitee_plugin
jenkinsgithub_branch_source
jenkinsgithub_branch_source_plugin
jenkinsgroovy
jenkinsgroovy_plugin
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.