
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-57299 is a missing permission check vulnerability in the Jenkins Contrast Continuous Application Security Plugin that allows authenticated attackers to enumerate the names of configured Contrast metadata. It affects plugin versions 3.11 and earlier, and was disclosed on June 24, 2026 as part of the Jenkins Security Advisory 2026-06-24 (tracked as SECURITY-3697 (2)). The vulnerability was reported by Kai Aizen (SnailSploit). It carries a CVSS v3.1 base score of 4.3 (Medium) (Jenkins Advisory, GitHub Advisory).
The root cause is CWE-862 (Missing Authorization): several HTTP endpoints in the plugin that populate list box options with configured Contrast metadata names do not enforce any permission checks before returning data. An attacker with only Overall/Read permission — the lowest level of authenticated access in Jenkins — can send requests to these endpoints and receive the names of all configured Contrast metadata entries. No special privileges, user interaction, or complex conditions are required beyond having a valid Jenkins account (Jenkins Advisory, GitHub Advisory).
Successful exploitation allows an authenticated low-privileged Jenkins user to enumerate the names of Contrast metadata configurations that should be restricted to administrators. While the direct impact is limited to information disclosure (no confidentiality impact on secrets, no availability impact), the exposed metadata names could assist an attacker in mapping the application security configuration and potentially support follow-on attacks. The CVSS scoring reflects a low integrity impact due to the unauthorized access to restricted resource listings (Jenkins Advisory, GitHub Advisory).
/descriptorByName/ related to the contrast-continuous-application-security plugin).Update the Contrast Continuous Application Security Plugin to version 3.12 or later, which requires the appropriate permission to enumerate configured Contrast metadata. The fix is available via the Jenkins Update Center as of June 24, 2026. As an interim measure, restrict Overall/Read access to trusted users only and audit which accounts have access to the Jenkins instance (Jenkins Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."