CVE-2026-57300: Jenkins Mcp Server
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.
Affected products
- Jenkins Mcp Server: up to and including 0.177.v629fdb_2557fe
Published 2026-06-24. Last modified 2026-06-26.