CVE-2026-57299
Jenkins vulnerability analysis and mitigation

Overview

CVE-2026-57299 is a missing permission check vulnerability in the Jenkins Contrast Continuous Application Security Plugin that allows authenticated attackers to enumerate the names of configured Contrast metadata. It affects plugin versions 3.11 and earlier, and was disclosed on June 24, 2026 as part of the Jenkins Security Advisory 2026-06-24 (tracked as SECURITY-3697 (2)). The vulnerability was reported by Kai Aizen (SnailSploit). It carries a CVSS v3.1 base score of 4.3 (Medium) (Jenkins Advisory, GitHub Advisory).

Technical details

The root cause is CWE-862 (Missing Authorization): several HTTP endpoints in the plugin that populate list box options with configured Contrast metadata names do not enforce any permission checks before returning data. An attacker with only Overall/Read permission — the lowest level of authenticated access in Jenkins — can send requests to these endpoints and receive the names of all configured Contrast metadata entries. No special privileges, user interaction, or complex conditions are required beyond having a valid Jenkins account (Jenkins Advisory, GitHub Advisory).

Impact

Successful exploitation allows an authenticated low-privileged Jenkins user to enumerate the names of Contrast metadata configurations that should be restricted to administrators. While the direct impact is limited to information disclosure (no confidentiality impact on secrets, no availability impact), the exposed metadata names could assist an attacker in mapping the application security configuration and potentially support follow-on attacks. The CVSS scoring reflects a low integrity impact due to the unauthorized access to restricted resource listings (Jenkins Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Jenkins instance with the Contrast Continuous Application Security Plugin version 3.11 or earlier installed. This can be done by checking the Jenkins plugin manager page (if accessible) or by probing known plugin-specific endpoints.
  2. Authenticate: Log in to the Jenkins instance with any valid account that has Overall/Read permission — the minimum permission level granted to most authenticated users.
  3. Access vulnerable endpoints: Send HTTP GET requests to the plugin's list box population endpoints (e.g., endpoints used to fill Contrast metadata dropdowns in job configuration forms) without providing elevated credentials.
  4. Enumerate metadata: Parse the HTTP responses to extract the names of all configured Contrast metadata entries, which are returned without authorization enforcement.
  5. Use gathered information: Leverage the enumerated metadata names to better understand the application security configuration, potentially informing further attacks against the Jenkins environment or the connected Contrast TeamServer (Jenkins Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP GET requests from low-privileged user accounts to Contrast plugin form-fill or list box endpoints (e.g., URLs under /descriptorByName/ related to the contrast-continuous-application-security plugin).
  • Logs: Jenkins access logs showing requests to Contrast plugin HTTP endpoints by accounts that do not normally interact with Contrast configuration; multiple rapid requests to metadata enumeration endpoints from a single user.
  • Behavior: Low-privileged accounts accessing plugin configuration endpoints that are not part of normal job build or read workflows.

Mitigation and workarounds

Update the Contrast Continuous Application Security Plugin to version 3.12 or later, which requires the appropriate permission to enumerate configured Contrast metadata. The fix is available via the Jenkins Update Center as of June 24, 2026. As an interim measure, restrict Overall/Read access to trusted users only and audit which accounts have access to the Jenkins instance (Jenkins Advisory).

Additional resources


SourceThis report was generated using AI

Related Jenkins vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-10050HIGH8.7
  • Java logoJava
  • apache-jena-fuseki
NoYesJul 22, 2026
CVE-2026-59889MEDIUM6.5
  • Java logoJava
  • flyway
NoYesJul 14, 2026
CVE-2026-59888MEDIUM6.5
  • Java logoJava
  • elasticsearch-fips-8.19
NoYesJul 14, 2026
CVE-2026-8384MEDIUM5.3
  • Java logoJava
  • confluent-kafka
NoYesJul 14, 2026
CVE-2026-6790MEDIUM5.3
  • Java logoJava
  • apache-nifi
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management