CVE-2026-92130 PUBLISHED

Assigner: jenkins
Reserved: 15.09.2026 Published: 16.09.2026 Updated: 16.09.2026

Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.

Product Status

Vendor Jenkins Project
Product Jenkins Pipeline: Multibranch Plugin
Versions Default: unaffected
  • affected from 0 to 841.vec5b_9e1806ec (incl.)

References