CVE-2026-57301High· 8.8▾ TwilightJenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.6%
Jenkins OWASP ZAP Plugin 1.0.7 and earlier does not support distributed builds, causing the file operations and build process of its "Automatically build ZAP" feature to be performed on the Jenkins controller rather than on the agent the build is assigned to.
This allows attackers with Item/Configure permission to configure the feature to build an attacker-controlled project, executing arbitrary code on the Jenkins controller and bypassing any restriction confining the build to a specific agent.
As of publication of this advisory, there is no fix.
org.jenkins-ci.plugins:zapper <= 1.0.7Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57303High· 7.1Jenkins Assembla Plugin has an XXE vulnerability
CVE-2026-57302Medium· 4.3Jenkins FitNesse Plugin stores passwords unencrypted
CVE-2026-57305Medium· 5.4Jenkins Assembla Plugin has a cross-site request forgery (CSRF) vulnerability
CVE-2026-57304Medium· 5.4Jenkins Assembla Plugin has a missing permission check
CVE-2026-57296High· 8.8Jenkins External Workspace Manager Plugin has a path traversal vulnerability
CVE-2026-57288Low· 3.7Jenkins Active Directory Plugin has an LDAP injection vulnerability