Threat · curated 23 Jul 2026
NVD - CVE-2026-57300
First reported nist.gov
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
CVE-2026-57300 affects a Model Context Protocol server plugin, illustrating how MCP integrations into CI/CD systems like Jenkins can expose sensitive pipeline data through inadequate authorization checks reachable by AI agents and users.
CVE-2026-57300 is a missing permission check in the Jenkins MCP Server Plugin (version 0.177.v629fdb_2557fe and earlier) that allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access. CISA-ADP scored it CVSS 3.1 4.3 (Medium), and a Jenkins security advisory dated 2026-06-24 addresses the flaw.