CVE-2026-57296: Path Traversal
Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jenkins External Workspace Manager Pluginto a version that resolves this vulnerability.Fixed in 1.3.2 and earlier does not reject path traversal sequences - Configuration
Update Jenkins External Workspace Manager Plugin so that the exwsAllocate step rejects path traversal sequences in the custom workspace path.
Jenkins External Workspace Manager Plugin exwsAllocate Pipeline step custom workspace path validation = reject path traversal sequences
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57296?
CVE-2026-57296 has a risk score of 66, indicating it is a medium severity vulnerability.
How do I fix CVE-2026-57296?
To fix CVE-2026-57296, upgrade the Jenkins External Workspace Manager Plugin to version 1.3.3 or later.
What type of vulnerability is CVE-2026-57296?
CVE-2026-57296 is a path traversal vulnerability that allows unauthorized file access on the Jenkins controller.
Who is affected by CVE-2026-57296?
Users with Item/Configure permission on Jenkins systems utilizing External Workspace Manager Plugin version 1.3.2 or earlier are affected by CVE-2026-57296.
What can attackers do with CVE-2026-57296?
Attackers exploiting CVE-2026-57296 can read arbitrary files on the Jenkins controller file system, potentially compromising sensitive information.