Vulnerability Details CVE-2026-57300
A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 7.5%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2026-57300
-
cpe:2.3:a:jenkins:mcp_server:0.86.v7d3355e6a_a_18