Jenkins MCP Server Plugin missing permission check exposes Pipeline replay scripts
A missing permission check in the Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access. The issue was published as CVE-2026-57300 alongside a Jenkins security advisory.
Disclosed 24 June 2026 · Record updated 13 September 2026
Impact
Users holding only Item/Read permission could read Pipeline replay scripts of jobs they can access, potentially disclosing sensitive script contents.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-57300
