Junglewise Threat Intelligence

CVE-2026-57295: Jenkins EC2 Fleet Plugin CSRF in AWS credential connection

CVE-2026-57295 · Severity: medium · CVSS 5.4 · Published 2026-06-24

Vendors: Maven, Jenkins Project.

Executive brief

The Jenkins EC2 Fleet Plugin, which manages Amazon EC2 instances for build tasks, contains a security flaw that could allow an attacker to steal AWS credentials. By tricking a logged-in user into clicking a malicious link, an attacker can force the plugin to connect to a server they control. This allows the attacker to capture sensitive AWS authentication keys stored within the Jenkins system, potentially leading to unauthorized access to the organization's cloud infrastructure.

Technical details

A cross-site request forgery (CSRF) vulnerability exists in the Jenkins EC2 Fleet Plugin versions 4.2.3.539.v8fedff2a_81c3 and earlier. The vulnerability resides in an HTTP endpoint that fails to implement proper CSRF protection, allowing an attacker to induce a victim to perform an action that connects Jenkins to an arbitrary URL. By specifying an attacker-controlled URL and a valid credentials ID (potentially obtained through other information disclosure vulnerabilities), the attacker can capture the AWS credentials associated with that ID when Jenkins attempts to authenticate against the malicious endpoint. This requires the attacker to successfully social engineer a user with sufficient permissions into visiting a malicious site or clicking a link while authenticated to Jenkins.

Affected products

  • Jenkins Project EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier

Timeline

  • 2026-06-24: disclosed: Initial advisory publication by Jenkins Project
  • 2026-06-24: advisory: NVD publication date

References

Related threats