Junglewise Threat Intelligence

CVE-2026-57290: Jenkins Priority Sorter Plugin CSRF in global job priority configuration

CVE-2026-57290 · Severity: medium · CVSS 4.3 · Published 2026-06-24

Vendors: Jenkins Project, Maven.

Executive brief

The Jenkins Priority Sorter Plugin, which allows administrators to manage the execution order of build jobs, contains a security flaw. An attacker could trick a logged-in administrator into clicking a malicious link, which would then automatically change the global job priority settings. This could disrupt normal operations by causing critical tasks to be delayed or less important tasks to take precedence.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Jenkins Priority Sorter Plugin through version 936.v2c01c6b_84449. The vulnerability is located in the HTTP endpoint responsible for saving global job priority configurations, which fails to implement proper crumb/token validation. An unauthenticated remote attacker can exploit this by inducing a Jenkins administrator to visit a specially crafted webpage. Successful exploitation allows the attacker to overwrite global plugin settings, potentially impacting the scheduling and execution order of all jobs on the Jenkins controller. As of the advisory date, a fix has not been specified in the provided text, though users are generally advised to update to the latest version.

Affected products

  • Jenkins Project Priority Sorter Plugin 936.v2c01c6b_84449 and earlier

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: advisory

References