CVE-2026-57296
EUVD-2026-3877724.06.2026, 14:17
Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code execution.
Awaiting analysis
This vulnerability is currently awaiting analysis.
Vulnerability Media Exposure