Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
References
Configurations
No configuration.
History
16 Sep 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.1 |
| CWE | CWE-863 |
16 Sep 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 14:17
Updated : 2026-09-16 20:17
NVD link : CVE-2026-92130
Mitre link : CVE-2026-92130
CVE.ORG link : CVE-2026-92130
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
