CVE-2026-57301
Jenkins Project Jenkins OWASP ZAP Plugin, official owasp zap
Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.
- CVSS
- 8.8
- EPSS
- 0.42% 34.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.24