Description
A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and service key.
Published: 2026-06-24
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing permission check in Jenkins Contrast Continuous Application Security Plugin versions 3.11 and earlier enables attackers who possess Overall or Read access in a Jenkins instance to configure the plugin to connect to an arbitrary external URL using an attacker-supplied username, API key, and service key. The flaw is an authorization bypass (CWE‑862) that allows the Jenkins server to initiate outbound connections to a target host specified by the attacker, potentially exfiltrating data or communicating with malicious services. The description provides no evidence of remote code execution; the impact scope is limited to unauthorized external network traffic.

Affected Systems

The vulnerability affects any Jenkins environment that has the Contrast Continuous Application Security Plugin 3.11 or earlier installed. Only installations where a user has Overall or Read permissions and can modify plugin configuration are susceptible. Systems that do not use this plugin or that deny the relevant permissions are not impacted.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation has been observed. The CVSS score is 5.4, reflecting moderate severity. Because Jenkins instances with Overall or Read privileges—users that may be numerous—can modify plugin configuration, affected installations can be considered at moderate to high risk. An attacker can cause the Jenkins server to send outbound traffic that may expose internal data or communicate with compromised services.

Generated by OpenCVE AI on August 3, 2026 at 07:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Jenkins Contrast Continuous Application Security Plugin to the latest available version, which removes the missing permission check.
  • If an upgrade is not feasible, uninstall or disable the vulnerable plugin to eliminate the code path.
  • Restrict Overall or Read permissions to the minimal set of users required for Jenkins operation to reduce the number of users able to modify plugin configuration.
  • Implement firewall or network segmentation rules to block the Jenkins server from making outbound connections to untrusted external hosts.

Generated by OpenCVE AI on August 3, 2026 at 07:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Allows Unauthorized External Connectivity in Jenkins Contrast Continuous Application Security Plugin

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Allows Unauthorized External Connectivity in Jenkins Contrast Continuous Application Security Plugin

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Enables Outbound Connectivity in Jenkins Contrast Plugin

Tue, 21 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Enables Outbound Connectivity in Jenkins Contrast Plugin

Thu, 16 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Missing permission check enables unauthorized external connectivity in Jenkins Contrast Continuous Application Security Plugin

Tue, 14 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Missing permission check enables unauthorized external connectivity in Jenkins Contrast Continuous Application Security Plugin

Mon, 13 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthorized External Connectivity via Plugin Permission Gap

Sat, 11 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthorized External Connectivity via Plugin Permission Gap

Thu, 09 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Allows Outbound Connections in Jenkins Contrast Continuous Application Security Plugin

Wed, 08 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Allows Outbound Connections in Jenkins Contrast Continuous Application Security Plugin

Tue, 07 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Enables Arbitrary Outbound Connections in Jenkins Contrast Plugin
Weaknesses CWE-284

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins contrast Continuous Application Security
Jenkins Project
Jenkins Project jenkins Contrast Continuous Application Security Plugin
Vendors & Products Jenkins
Jenkins contrast Continuous Application Security
Jenkins Project
Jenkins Project jenkins Contrast Continuous Application Security Plugin

Wed, 24 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Enables Arbitrary Outbound Connections in Jenkins Contrast Plugin
Weaknesses CWE-284

Wed, 24 Jun 2026 13:45:00 +0000

Type Values Removed Values Added
Description A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and service key.
References

Subscriptions

Jenkins Contrast Continuous Application Security
Jenkins Project Jenkins Contrast Continuous Application Security Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-07-06T14:39:42.374Z

Reserved: 2026-06-24T08:41:44.358Z

Link: CVE-2026-57297

cve-icon Vulnrichment

Updated: 2026-06-24T14:40:00.247Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T07:15:04Z

Weaknesses