
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-57294 is a missing permission check vulnerability in the Jenkins EC2 Fleet Plugin that allows low-privileged attackers to capture AWS credentials stored in Jenkins. It affects EC2 Fleet Plugin versions up to and including 4.2.3.539.v8fedff2a_81c3 and was disclosed on June 24, 2026, as part of the Jenkins Security Advisory SECURITY-3774. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Jenkins Advisory, GitHub Advisory). It was reported by dyingman1 (redpoc Offensive Security Team) (Jenkins Advisory).
The root cause is CWE-862 (Missing Authorization): the EC2 Fleet Plugin fails to perform permission checks in several HTTP endpoints used to validate cloud configurations (GitHub Advisory). An attacker with only Overall/Read permission can send requests to these form validation endpoints, supplying an attacker-controlled URL and credential IDs obtained through a separate method, causing the Jenkins server to connect to the attacker's URL and transmit the referenced AWS credentials (Jenkins Advisory). A companion vulnerability, CVE-2026-57295, covers the CSRF aspect of the same endpoints, which accept GET requests and thus do not require POST, enabling cross-site request forgery attacks (Jenkins Advisory).
Successful exploitation allows an attacker with minimal Jenkins access (Overall/Read) to exfiltrate AWS credentials stored in Jenkins by causing the server to make an outbound connection to an attacker-controlled endpoint. Captured AWS credentials could then be used to access, modify, or destroy cloud resources in the victim's AWS environment, potentially enabling lateral movement into cloud infrastructure, data exfiltration, or resource abuse. There is no availability impact, but both confidentiality and integrity are partially affected (Jenkins Advisory, GitHub Advisory).
nc -lvp 8080 or Burp Collaborator) to capture incoming connections and credential data./descriptorByName/com.amazon.jenkins.ec2_fleet.*) from low-privileged user accounts; requests with unusual or external url parameters.Update the Jenkins EC2 Fleet Plugin to version 4.2.3.540.va_6eedb_7b_c112 or later, which requires Overall/Administer permission and POST requests for the affected form validation endpoints (Jenkins Advisory). If an immediate upgrade is not possible, restrict Overall/Read access to trusted users only and monitor Jenkins for unexpected outbound connections. Additionally, rotate any AWS credentials stored in Jenkins as a precautionary measure if exposure is suspected.
The vulnerability was disclosed as part of a broad Jenkins security advisory on June 24, 2026, covering over 20 vulnerabilities across multiple plugins. Coverage appeared on security aggregation sites including CyberPress and various CVE tracking platforms shortly after disclosure (Feedly). No notable individual researcher commentary or significant social media discussion specific to CVE-2026-57294 has been identified beyond standard advisory republication.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."