CVE-2026-57296

Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code execution.
Configurations

No configuration.

History

24 Jun 2026, 16:16

Type Values Removed Values Added
CWE CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

24 Jun 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-24 14:17

Updated : 2026-06-25 14:01


NVD link : CVE-2026-57296

Mitre link : CVE-2026-57296

CVE.ORG link : CVE-2026-57296


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')