CVE-2026-57285: Medium severity Jenkins GitHub Branch Source Plugin vulnerability
A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers configured in the global plugin configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jenkins GitHub Branch Source Pluginto a version that resolves this vulnerability.Fixed in 1967.1969.v205fd594c821
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57285?
CVE-2026-57285 has a medium severity score of 4.3.
How do I fix CVE-2026-57285?
To fix CVE-2026-57285, update to the Jenkins GitHub Branch Source Plugin version 1969 or later.
What does CVE-2026-57285 allow attackers to do?
CVE-2026-57285 allows attackers with Overall/Read permission to access the URLs of configured GitHub Enterprise servers.
Which software is affected by CVE-2026-57285?
CVE-2026-57285 affects Jenkins GitHub Branch Source Plugin versions 1967 and earlier.
When was CVE-2026-57285 published?
CVE-2026-57285 was published on June 24, 2026.