CVE-2026-57286Medium· 4.3▾ SunlitJenkins Git Parameter Plugin has a missing permission check that allows listing SCM branch and tag names
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.3%
Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier does not perform a permission check in an HTTP endpoint that populates the list of values for Git parameters by querying the SCM configured on a job, using the SCM credentials configured in Jenkins.
This allows attackers with Item/Read permission to obtain information about the SCM repository used by a job they would otherwise be unable to access, such as branch names, tag names, and revision metadata.
Git Parameter Plugin 462.463.v496a_59f698e5 requires Item/Build permission to populate the list of values for Git parameters.
org.jenkins-ci.tools:git-parameter < 462.463Upgrade to a patched release:
org.jenkins-ci.tools:git-parameter 462.463Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57304Medium· 5.4Jenkins Assembla Plugin has a missing permission check
CVE-2026-57293Medium· 4.3Jenkins Gitee Plugin has an incorrect permission check that allows enumerating credentials IDs
CVE-2026-57291Medium· 5.4Jenkins Gitee Plugin missing permission checks
CVE-2026-57285Medium· 4.3Jenkins GitHub Branch Source Plugin has missing permission check that allows enumerating GitHub Enterprise server URLs
CVE-2026-57301High· 8.8Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE
CVE-2026-57303High· 7.1Jenkins Assembla Plugin has an XXE vulnerability