CVE-2026-92130

Summary

Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.

Affected Software

VendorProductVersion RangeStatus
Jenkins ProjectJenkins Pipeline: Multibranch Plugin0 <= 841.vec5b_9e1806ecaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References