
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-57297 is a missing permission check vulnerability in the Jenkins Contrast Continuous Application Security Plugin (versions 3.11 and earlier) that allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and service key. It is part of a broader security advisory (SECURITY-3697 (1)) that also covers a related CSRF issue (CVE-2026-57298). The vulnerability was disclosed on June 24, 2026, and has a CVSS v3.1 base score of 4.3 (Medium) (Jenkins Advisory, GitHub Advisory).
The root cause is CWE-862 (Missing Authorization): the plugin's HTTP endpoint for testing connections to a Contrast TeamServer does not enforce any permission check beyond the basic Overall/Read permission, which is typically granted to all authenticated users. An attacker can craft a request to this endpoint supplying arbitrary URL, username, API key, and service key values, causing the Jenkins server to initiate an outbound connection to an attacker-controlled host. Additionally, the endpoint accepts GET requests (no POST requirement), enabling cross-site request forgery (CSRF) attacks as a companion vector (CVE-2026-57298). The vulnerability was reported by Kai Aizen (SnailSploit) (Jenkins Advisory).
Exploitation allows a low-privileged authenticated attacker (or, via CSRF, an unauthenticated attacker tricking a logged-in user) to cause the Jenkins controller to make outbound HTTP connections to arbitrary attacker-controlled URLs, potentially enabling server-side request forgery (SSRF) against internal network resources. The integrity impact is low — attackers can influence connection behavior but cannot directly read or exfiltrate Jenkins credentials through this specific flaw. Availability and confidentiality are not directly impacted by CVE-2026-57297 alone, though the SSRF capability could be chained with other vulnerabilities for broader compromise (Jenkins Advisory, GitHub Advisory).
contrast or teamserver in the URL) with unusual or external host parameters; repeated requests from low-privileged user accounts.Update the Contrast Continuous Application Security Plugin to version 3.12 or later, which requires Overall/Administer permission and POST requests to test the connection to a Contrast TeamServer, eliminating both the missing permission check and the CSRF vector (Jenkins Advisory). As an interim workaround, restrict Overall/Read access to trusted users only, and consider blocking outbound connections from the Jenkins controller to untrusted external hosts via network-level controls. Administrators should also review and apply all other fixes from the June 24, 2026 Jenkins security advisory, as multiple plugins were affected simultaneously.
The vulnerability was disclosed as part of a broad Jenkins security advisory covering over 20 CVEs across 18 plugins, which received coverage from standard vulnerability tracking services including Tenable (Nessus plugin 322478), OSS-Sec mailing list, and VulnDB. No notable independent researcher commentary or significant social media discussion specific to CVE-2026-57297 has been identified beyond routine advisory aggregation (Jenkins Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."