CVE-2026-57300Medium· 4.3▾ SunlitJenkins MCP Server Plugin missing a permission check
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.3%
Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier does not perform a permission check in the getReplayScripts MCP tool that returns the replay script of a Pipeline build.
This allows attackers with Item/Read permission to obtain the Pipeline script of jobs.
MCP Server Plugin 0.178.vffe5a_e770f3b_ requires Item/Extended Read permission to return the replay script of a Pipeline build through the getReplayScripts MCP tool.
io.jenkins.plugins:mcp-server < 0.178.vffe5aUpgrade to a patched release:
io.jenkins.plugins:mcp-server 0.178.vffe5aConnected by shared product, vendor, weakness, or advisory.
CVE-2026-57307Medium· 4.2Jenkins Zowe zDevOps Plugin has a missing permission check
CVE-2026-57299Medium· 4.3Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers with Overall/Read permission to enumerate the names of configured Contrast metadata.
CVE-2026-57297Medium· 4.3A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, a…
CVE-2026-84659Medium· 4.3Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through St…
CVE-2026-84657Medium· 4.2In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permissi…
CVE-2026-84656Medium· 4.3A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to.