CVE-2026-57286 Details
Description
A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used by a job, such as branch names, tag names, and revision metadata.
A vulnerability exists in the Git Parameter Plugin for Jenkins, specifically in versions through 462.vdcf3df2ed2ca_. The issue arises from a missing permission check that allows attackers with Item/Read permission to access information about the SCM repository associated with a job. This includes details such as branch names, tag names, and revision metadata. The vulnerability is exploited by querying an HTTP endpoint that populates Git parameter values based on the SCM configuration of a job, using the SCM credentials stored in Jenkins.
Users of the Git Parameter Plugin should update to version 462.463.v496a_59f698e5, which requires Item/Build permission to populate the list of values for Git parameters.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3745 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| jenkins git parameter | <= 462.vdcf3df2ed2ca |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | Initial Analysis | [email protected] |
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |