CVE-2026-57300: Medium severity Jenkins MCP Server Plugin vulnerability
Published Jun 24, 2026
·Updated
A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.
Affected Software
2 affected components
Jenkins MCP Server Plugin<=0.177.v629fdb_2557fe
Jenkins Mcp Server Jenkins<=0.177.v629fdb_2557fe
Event History
Jun 24, 2026
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
Description
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-57300?
CVE-2026-57300 has a risk rating of 33, indicating a moderate severity level.
2
How do I fix CVE-2026-57300?
To remediate CVE-2026-57300, update the Jenkins MCP Server Plugin to version 0.178 or later.
3
What kind of attacks can exploit CVE-2026-57300?
Attackers with Item/Read permission can exploit CVE-2026-57300 to access Pipeline replay scripts of accessible jobs.
4
Which versions of Jenkins MCP Server Plugin are affected by CVE-2026-57300?
Jenkins MCP Server Plugin versions 0.177.v629fdb_2557fe and earlier are affected by CVE-2026-57300.
5
What permissions are needed to exploit CVE-2026-57300?
Exploitation of CVE-2026-57300 requires the attacker to have Item/Read permission.