PT-2026-51803 · Jenkins · Jenkins Git Plugin

Published

2026-06-24

·

Updated

2026-06-24

·

CVE-2026-57293

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
An incorrect permission check in Jenkins Gitee Plugin 1288.v18b deb c9069b and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57293

Affected Products

Jenkins Git Plugin