Vulnerability intelligence
CVE-2026-57296
Jenkins Project Jenkins External Workspace Manager Plugin
Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code execution.
CVSS Score
8.8
High
EPSS — Exploit Probability
0.8%
Riskier than 56% of all CVEs · checked 2026-09-20
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Jun 25, 2026 · latest Jun 25, 2026
Coverage timeline
-
Jenkins patches 22 flaws, warns of RCE via CVE-2026-57281securityonline.info · Jun 25, 2026