CVE-2026-57281
Summary
| CVE | CVE-2026-57281 |
|---|---|
| State | PUBLISHED |
| Assigner | jenkins |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-24 14:17:34 UTC |
| Updated | 2026-08-27 13:18:25 UTC |
| Description | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates the script. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from ADP
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.008890000 probability, percentile 0.567400000 (date 2026-08-27)
Problem Types: CWE-93 | CWE-693 | CWE-917 | CWE-693 CWE-693 Protection Mechanism Failure | CWE-93 CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') | CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 7.5 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | ADP | CVSS | 8.5 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | Secondary | 8.5 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jenkins | Script Security | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Jenkins Project | Jenkins Script Security Plugin | affected 1402.v94c9ce464861 maven | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.12 | unaffected 1786628667 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.13 | unaffected 1786628681 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.14 | unaffected 1786533561 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.15 | unaffected 1786533565 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.16 | unaffected 1787125166 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.17 | unaffected 1787124635 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.18 | unaffected 1787125069 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.19 | unaffected 1787124632 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.20 | unaffected 1787124925 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.21 | unaffected 1787125311 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.22 | unaffected 1787124779 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services | Not specified | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.jenkins.io/security/advisory/2026-06-24 | [email protected] | www.jenkins.io | Vendor Advisory |
| access.redhat.com/errata/RHSA-2026:60250 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60248 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60247 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2026-57281 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60252 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| bugzilla.redhat.com/show_bug.cgi | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60259 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60256 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57281.json | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | security.access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60239 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60254 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60251 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60246 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60249 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2026-06-24T14:02:12.873Z | Reported to Red Hat. |
| ADP | 2026-06-24T13:20:04.648Z | Made public. |
Solutions
ADP: RHSA-2026:60247: OpenShift Developer Tools and Services 4.12
ADP: RHSA-2026:60249: OpenShift Developer Tools and Services 4.13
ADP: RHSA-2026:60248: OpenShift Developer Tools and Services 4.14
ADP: RHSA-2026:60239: OpenShift Developer Tools and Services 4.15
ADP: RHSA-2026:60251: OpenShift Developer Tools and Services 4.16
ADP: RHSA-2026:60246: OpenShift Developer Tools and Services 4.17
ADP: RHSA-2026:60250: OpenShift Developer Tools and Services 4.18
ADP: RHSA-2026:60252: OpenShift Developer Tools and Services 4.19
ADP: RHSA-2026:60259: OpenShift Developer Tools and Services 4.20
ADP: RHSA-2026:60254: OpenShift Developer Tools and Services 4.21
ADP: RHSA-2026:60256: OpenShift Developer Tools and Services 4.22
Workarounds
ADP: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.