Junglewise Threat Intelligence

CVE-2026-57296: Jenkins External Workspace Manager Plugin path traversal in exwsAllocate

CVE-2026-57296 · Severity: high · CVSS 8.8 · Published 2026-06-24

Vendors: Jenkins Project, Maven.

Executive brief

The Jenkins External Workspace Manager Plugin, which helps manage disk space for build jobs, contains a security flaw that allows users with job configuration permissions to access files outside of their designated workspace. By exploiting this path traversal vulnerability, an attacker can read sensitive system files on the Jenkins controller. This access can be further leveraged to execute unauthorized commands, potentially leading to a full takeover of the Jenkins server and disruption of the software delivery pipeline.

Technical details

The Jenkins External Workspace Manager Plugin fails to properly validate or sanitize path traversal sequences (e.g., '../') in the custom workspace path provided to the 'exwsAllocate' Pipeline step. An attacker with 'Item/Configure' permissions can provide a malicious path that escapes the intended workspace directory to access arbitrary files on the Jenkins controller file system. Because Jenkins controller file access often includes sensitive configuration and credentials, this vulnerability can be escalated to achieve remote code execution (RCE). The issue is present in version 1.3.2 and all prior versions. Users should update to a patched version if available or restrict configuration permissions.

Affected products

  • Jenkins Project External Workspace Manager Plugin <= 1.3.2

Timeline

  • 2026-06-24: disclosed: Initial advisory publication
  • 2026-06-24: advisory: Jenkins Security Advisory 2026-06-24 published

References