PT-2026-51806 · Jenkins · External Workspace Manager Plugin

CVE-2026-57296

·

Published

2026-06-24

·

Updated

2026-06-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins External Workspace Manager Plugin versions prior to 1.3.3
Description The plugin fails to reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step. This allows attackers with Item/Configure permissions to read arbitrary files on the Jenkins controller file system, which may lead to remote code execution. Path traversal is a technique used to access files and directories that are stored outside the web root folder by manipulating variables such as file paths.
Recommendations Update Jenkins External Workspace Manager Plugin to version 1.3.3 or later. As a temporary mitigation, restrict Item/Configure permissions to trusted users only.

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57296

Affected Products

External Workspace Manager Plugin