CVE-2026-57296

Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code execution.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-24 14:17

Updated : 2026-06-25 14:01


NVD link : CVE-2026-57296

Mitre link : CVE-2026-57296

CVE.ORG link : CVE-2026-57296


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')