Boletines de Vulnerabilidades |
CVE-2026-57296 |
|
| Software afectado | JENKINS |
| Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code execution. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-57296 | |














