CVE-2026-57304: Medium severity Jenkins Assembla Plugin vulnerability
Published Jun 24, 2026
·Updated
A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username and password.
Affected Software
2 affected components
Jenkins Assembla Plugin<=1.4
Jenkins Assembla Jenkins<=1.4
Event History
Jun 24, 2026
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
Description
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-57304?
The severity of CVE-2026-57304 is rated as 40.
2
How do I fix CVE-2026-57304?
To fix CVE-2026-57304, update the Jenkins Assembla Plugin to version 1.4.1 or later.
3
What components are affected by CVE-2026-57304?
CVE-2026-57304 specifically affects the Jenkins Assembla Plugin versions 1.4 and earlier.
4
What type of vulnerability is CVE-2026-57304?
CVE-2026-57304 is a missing permission check vulnerability that allows unauthorized access.
5
Who can exploit CVE-2026-57304?
Attackers with Overall/Read permission can exploit CVE-2026-57304 to connect to an attacker-specified URL.