Description
A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins.
Published: 2026-06-24
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing permission check in the Jenkins EC2 Fleet Plugin allows a user with only Overall/Read access to instruct the plugin to connect to any URL that the attacker provides. By supplying a credentials ID that the attacker has acquired elsewhere, the plugin will use that ID to authenticate to the target, resulting in the exfiltration of any AWS credentials stored in Jenkins. This flaw enables an attacker to obtain privileged AWS access without requiring elevated Jenkins permissions, compromising the confidentiality of cloud credentials and potentially all resources associated with them.

Affected Systems

The Jenkins EC2 Fleet Plugin versions 4.2.3.539.v8fedff2a_81c3 and all earlier releases are affected. Deployments using these plugin versions are vulnerable regardless of other Jenkins components.

Risk and Exploitability

The CVSS score is 5.4, and the EPSS score is unavailable, so the quantitative risk is moderate. The attack only needs Overall/Read privilege—common in many Jenkins installations—and a valid credentials ID, which can be obtained by other means. Because the exploit is a simple outbound request to an attacker‑supplied URL, it can be carried out from any network host that can reach the Jenkins instance. The vulnerability is not listed in the CISA KEV catalog, indicating no publicized exploitation yet, but the potential to expose AWS credentials represents a moderate‑to‑high impact risk.

Generated by OpenCVE AI on June 24, 2026 at 16:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Jenkins EC2 Fleet Plugin to the latest version that removes the missing permission check.
  • Restrict Jenkins permissions so that only trusted users have Overall/Read rights or higher, limiting who can invoke the plugin.
  • Configure firewall or outbound network rules to whitelist only approved cloud service endpoints for Jenkins, preventing arbitrary connections to untrusted URLs.
  • Ensure all credentials IDs used by the plugin are stored in a secure credentials store and access control is enforced.

Generated by OpenCVE AI on June 24, 2026 at 16:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 24 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Enables Credential Theft via Jenkins EC2 Fleet Plugin
Weaknesses CWE-284
CWE-639

Wed, 24 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
Title Missing Permission Check in Jenkins EC2 Fleet Plugin Enables Credential Theft Missing Permission Check Enables Credential Theft via Jenkins EC2 Fleet Plugin

Wed, 24 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
Title Missing Permission Check in Jenkins EC2 Fleet Plugin Enables Credential Theft
Weaknesses CWE-284
CWE-639

Wed, 24 Jun 2026 13:45:00 +0000

Type Values Removed Values Added
Description A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-06-24T14:46:33.242Z

Reserved: 2026-06-24T08:41:44.358Z

Link: CVE-2026-57294

cve-icon Vulnrichment

Updated: 2026-06-24T14:46:26.341Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-24T17:00:13Z

Weaknesses