CVE-2026-57291: Medium severity Jenkins Gitee Plugin vulnerability
Published Jun 24, 2026
·Updated
Missing permission checks in Jenkins Gitee Plugin 1288.v18bdebc9069b and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method.
Affected Software
1 affected component
Jenkins Gitee Plugin<=1288.v18b_deb_c9069b_
Event History
Jun 24, 2026
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
Description
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-57291?
CVE-2026-57291 has a risk score of 33, indicating moderate severity.
2
How do I fix CVE-2026-57291?
To fix CVE-2026-57291, update the Jenkins Gitee Plugin to version 1288.v18b_deb_c9069b_ or later.
3
Who is affected by CVE-2026-57291?
Users of the Jenkins Gitee Plugin version 1288.v18b_deb_c9069b_ and earlier are affected by CVE-2026-57291.
4
What type of vulnerability is CVE-2026-57291?
CVE-2026-57291 is a vulnerability related to missing permission checks.
5
What impact does CVE-2026-57291 have on Jenkins instances?
CVE-2026-57291 allows attackers with Overall/Read permission to connect to attacker-specified URLs using stolen credentials.