CVE-2026-57290: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter Plugin 936.v2c01c6b84449 and earlier allows attackers to overwrite the global job priority configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jenkins Priority Sorter Pluginto a version that resolves this vulnerability.Fixed in 936.v2c01c6b_84449
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57290?
The severity of CVE-2026-57290 is medium with a CVSS score of 4.3.
What type of vulnerability is CVE-2026-57290?
CVE-2026-57290 is a cross-site request forgery (CSRF) vulnerability.
How can I mitigate CVE-2026-57290?
Mitigating CVE-2026-57290 involves ensuring that users are authenticated and implementing CSRF protection measures in Jenkins.
Which versions of the Jenkins Priority Sorter Plugin are affected by CVE-2026-57290?
CVE-2026-57290 affects Jenkins Priority Sorter Plugin version 936.v2c01c6b_84449 and earlier.
What can attackers achieve by exploiting CVE-2026-57290?
By exploiting CVE-2026-57290, attackers can overwrite the global job priority configuration in Jenkins.