CVE-2026-57287: Medium severity Jenkins Job Configuration History Plugin vulnerability

Published Jun 24, 2026
·
Updated

Jenkins Job Configuration History Plugin 1356.ve360da6c523a and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations, allowing attackers with Extended Read permission to view encrypted secret values that would otherwise be redacted.

Affected Software

2 affected components
Jenkins Job Configuration History Plugin<=1356.ve360da_6c523a_
Jenkins Job Configuration History Jenkins<=1356.ve360da_6c523a

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Jenkins Job Configuration History Plugin to a version that resolves this vulnerability.

    Fixed in 1356.ve360da_6c523a_Patch Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_
  2. Compensating control

    Reduce users with Extended Read permission to only those who require it, since attackers with Extended Read permission could view encrypted secret values that are not redacted in historical job and agent configurations.

Event History

Jun 24, 2026
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
Description
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-57287?

CVE-2026-57287 has a risk rating of 37, indicating significant severity.

2

How do I fix CVE-2026-57287?

To fix CVE-2026-57287, update the Jenkins Job Configuration History Plugin to version 1357 or later.

3

What does CVE-2026-57287 affect?

CVE-2026-57287 affects the Jenkins Job Configuration History Plugin version 1356.ve360da_6c523a_ and earlier.

4

Who is at risk from CVE-2026-57287?

Attackers with Extended Read permission are at risk of exploiting CVE-2026-57287 to view sensitive encrypted secret values.

5

What are the consequences of CVE-2026-57287?

CVE-2026-57287 can lead to the exposure of sensitive information, as encrypted secret values are visible in historical configurations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203