Junglewise Threat Intelligence

CVE-2026-57307: Jenkins Zowe zDevOps Plugin missing permission check in connection endpoint

CVE-2026-57307 · Severity: medium · CVSS 4.2 · Published 2026-06-24

Vendors: Jenkins Project, Maven.

Executive brief

The Jenkins Zowe zDevOps plugin, which integrates Jenkins with Zowe mainframe services, contains a security flaw where it fails to verify user permissions for certain actions. This allows an authorized Jenkins user to trick the system into connecting to a malicious server using existing credentials stored in Jenkins. An attacker could use this to steal sensitive login information or service credentials, potentially compromising connected mainframe systems.

Technical details

A missing permission check in Jenkins Zowe zDevOps Plugin version 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/Read permission to trigger an outbound connection to an arbitrary URL. By specifying a malicious endpoint and a known credential ID (obtained through other means), the attacker can cause the plugin to transmit Jenkins-stored credentials to the external server. This is a classic credential capture vulnerability resulting from improper authorization on a diagnostic or connection-testing endpoint. As of the advisory date, users should check for updates to the Zowe zDevOps Plugin.

Affected products

  • Jenkins Project Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: advisory

References

Related threats