Back to overview

CVE-2026-57300

Description
A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.

Metadata

CVE ID
CVE-2026-57300
State
PUBLISHED
Assigner
jenkins
Reserved
2026-06-24 08:41 UTC
Published
2026-06-24 13:20 UTC
Last updated
2026-06-24 13:20 UTC
Vendor / Product
Jenkins Project / Jenkins MCP Server Plugin
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Jenkins Project Jenkins MCP Server Plugin 0.172.174.v9f72da_90a_710, 0.178.vffe5a_e770f3b_ < *
References (1)
Back to overview