CVE-2026-57301: Jenkins Official Owasp Zap

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.

Affected products

  • Jenkins Official Owasp Zap: up to and including 1.0.7

Published 2026-06-24. Last modified 2026-06-26.