CVE-2026-57283: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration other than Pipeline steps through the Pipeline Snippet Generator.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jenkins Pipeline: Groovy Pluginto a version that resolves this vulnerability.Fixed in 4331.v9d06ed4658ff
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57283?
CVE-2026-57283 has a medium severity rating of 4.3 according to CVSS 3.1.
What types of attacks are possible with CVE-2026-57283?
CVE-2026-57283 allows attackers to perform cross-site request forgery (CSRF) attacks that can instantiate types related to job or system configuration.
How do I fix CVE-2026-57283?
To mitigate CVE-2026-57283, upgrade Jenkins Pipeline: Groovy Plugin to version 4332 or later.
What software is affected by CVE-2026-57283?
CVE-2026-57283 affects Jenkins Pipeline: Groovy Plugin version 4331.v9d06ed4658ff and earlier.
When was CVE-2026-57283 published?
CVE-2026-57283 was published on June 24, 2026.