
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-57290 is a Cross-Site Request Forgery (CSRF) vulnerability in the Jenkins Priority Sorter Plugin that allows unauthenticated attackers to overwrite the global job priority configuration by tricking an authenticated user into visiting a malicious page. It affects Priority Sorter Plugin versions 936.v2c01c6b_84449 and earlier. The vulnerability was disclosed on June 24, 2026, as part of the Jenkins Security Advisory SECURITY-3769. It carries a CVSS v3.1 base score of 4.3 (Medium) (Jenkins Advisory, GitHub Advisory).
The root cause is classified as CWE-352 (Cross-Site Request Forgery): the affected HTTP endpoint in the Priority Sorter Plugin that saves the global job priority configuration does not require POST requests and lacks CSRF token validation, allowing it to be triggered via a crafted GET request from any origin. An attacker can host a malicious web page containing a forged request to the vulnerable endpoint; when an authenticated Jenkins user visits the page, their browser automatically submits the request with their session credentials, causing the plugin to overwrite the global job priority configuration without the user's knowledge. No privileges are required on the attacker's side, but user interaction (the victim must be authenticated and visit the attacker-controlled page) is a prerequisite (Jenkins Advisory, GitHub Advisory).
Successful exploitation allows an attacker to overwrite the global job priority configuration in Jenkins, potentially disrupting the scheduling and execution order of CI/CD jobs across the entire Jenkins instance. The impact is limited to integrity — there is no confidentiality or availability impact — but tampering with job priorities could cause critical builds to be deprioritized or lower-priority jobs to consume resources, indirectly affecting pipeline reliability. The vulnerability does not enable code execution or credential theft on its own (Jenkins Advisory, GitHub Advisory).
<img>, <form>, or <script> tag) that automatically submits a GET request to the vulnerable Jenkins endpoint with attacker-controlled priority configuration parameters.Update the Jenkins Priority Sorter Plugin to version 936.937.v5581d0b_2ccb_a_ or later, which enforces POST requests for the affected configuration-save endpoint, preventing CSRF exploitation. As a general defense-in-depth measure, enforce Content Security Policy (CSP) headers on the Jenkins instance and ensure users are educated not to click suspicious links while authenticated. No configuration-only workaround is available for unpatched versions beyond disabling the Priority Sorter Plugin entirely (Jenkins Advisory).
The vulnerability was disclosed as part of a broader Jenkins Security Advisory on June 24, 2026, covering 18 plugins. Coverage was picked up by security aggregators including CVEFeed, VulnDB, and CyberPress shortly after disclosure. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-57290 has been observed, consistent with its moderate severity rating (Jenkins Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."