Junglewise Threat Intelligence

CVE-2026-57306: Jenkins Zowe zDevOps Plugin CSRF in credential connection endpoint

CVE-2026-57306 · Severity: medium · CVSS 4.2 · Published 2026-06-24

Vendors: Jenkins Project, Maven.

Executive brief

The Jenkins Zowe zDevOps Plugin, which integrates Jenkins with Zowe for mainframe DevOps, contains a security flaw that could allow an attacker to steal stored credentials. By tricking a logged-in user into clicking a malicious link, an attacker can force the plugin to connect to a server they control. This allows the attacker to capture sensitive login information stored within Jenkins, potentially leading to unauthorized access to other systems.

Technical details

A cross-site request forgery (CSRF) vulnerability exists in the Jenkins Zowe zDevOps Plugin version 1.1.3.50.ve350c9b_450b_1 and earlier. The vulnerability allows an attacker to force a victim's browser to send a request to a specific HTTP endpoint that initiates a connection to an arbitrary URL. By specifying an attacker-controlled URL and providing credential IDs (which must be obtained through separate means), the attacker can capture the credentials stored in Jenkins as the plugin attempts to authenticate against the malicious server. As of the advisory date, no patch has been explicitly detailed in the provided text, though the vulnerability is identified as SECURITY-3747.

Affected products

  • Jenkins Project Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier

Timeline

  • 2026-06-24: disclosed: Advisory published by Jenkins Project

References

Related threats