VulnWatch VulnWatch
← Back to dashboard
Medium nvd · CVE-2026-57300

CVE-2026-57300: A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read

Published Jun 24, 2026 CVSS 4.3

A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.

Affected AI Products

mcp server
Get the weekly digest. Every Monday: top AI security stories of the week. Free.