cbcvebase.
CVE-2026-57307
published 2026-06-24

CVE-2026-57307: A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/Read permission to connect to an…

PriorityP424medium4.2CVSS 3.1
AVNACHPRLUINSUCLILAN
EPSS
0.14%
3.7th percentile
A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsactive_directory
jenkinsactive_directory_plugin
jenkinsassembla
jenkinsassembla_plugin
jenkinsbitbucket_push_and_pull_request
jenkinsbitbucket_push_and_pull_request_plugin
jenkinscontrast_continuous_application_security
jenkinscontrast_continuous_application_security_plugin
jenkinsec2_fleet
jenkinsec2_fleet_plugin
jenkinsexternal_workspace_manager
jenkinsexternal_workspace_manager_plugin
jenkinsfitnesse
jenkinsfitnesse_plugin
jenkinsgit_client
jenkinsgit_client_plugin
jenkinsgit_parameter
jenkinsgit_parameter_plugin
jenkinsgitee
jenkinsgitee_plugin
jenkinsgithub_branch_source
jenkinsgithub_branch_source_plugin
jenkinsgroovy
jenkinsgroovy_plugin
jenkinsjenkins_controller_by_owasp_zap
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.