CVE-2026-57286: Medium severity Jenkins Git Parameter Plugin vulnerability
A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used by a job, such as branch names, tag names, and revision metadata.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57286?
The severity of CVE-2026-57286 is classified as medium with a CVSS score of 4.3.
What can attackers do with CVE-2026-57286?
Attackers with Item/Read permission can obtain sensitive information about the SCM repository, including branch names and revision metadata.
How do I fix CVE-2026-57286?
To fix CVE-2026-57286, upgrade to a patched version of the Jenkins Git Parameter Plugin that is later than version 462.vdcf3df2ed2ca_.
What versions are affected by CVE-2026-57286?
Versions of Jenkins Git Parameter Plugin up to and including 462.vdcf3df2ed2ca_ are affected by CVE-2026-57286.
Is CVE-2026-57286 exploitable remotely?
Yes, CVE-2026-57286 can be exploited remotely by attackers with the appropriate permissions.