Junglewise Threat Intelligence

CVE-2026-57300: Jenkins MCP Server Plugin missing permission check in Pipeline replay scripts

CVE-2026-57300 · Severity: medium · CVSS 4.3 · Published 2026-06-24

Vendors: Maven, Jenkins Project.

Executive brief

The Jenkins MCP Server Plugin, which facilitates communication between Jenkins and Model Context Protocol servers, contains a security flaw where it fails to properly verify user permissions. This allows an authorized Jenkins user who has basic read access to a project to view sensitive Pipeline replay scripts that they should not be able to see. This could lead to the exposure of proprietary build logic or sensitive information contained within those scripts.

Technical details

A missing permission check vulnerability exists in the Jenkins MCP Server Plugin versions 0.177.v629fdb_2557fe and earlier. The vulnerability is located in the component responsible for handling Pipeline replay scripts. An attacker with 'Item/Read' permission can bypass intended access controls to read the content of replay scripts for any job they have read access to, even if they lack the higher-level permissions normally required to view such scripts. This occurs because the plugin does not explicitly verify if the requesting user has the appropriate authorization to access the replay data. The issue is addressed in version 0.178.vffe5a_e770f3b_ and later.

Affected products

  • Jenkins Project MCP Server Plugin 0.177.v629fdb_2557fe and earlier

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: advisory

References

Related threats