CVE-2026-57301
EUVD-2026-3878224.06.2026, 14:17
Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| jenkins | owasp_zap | 𝑥 ≤ 1.0.7 | CNA |
Common Weakness Enumeration
Vulnerability Media Exposure