Description
A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Published: 2026-08-05
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A cross‑site request forgery vulnerability in the Jenkins SCM‑Manager Plugin (versions 1.11.1 and earlier) allows an attacker to force Jenkins to connect to an arbitrary, attacker‑specified URL using credentials IDs that have been obtained through another avenue. The attacker can capture credentials that are stored in Jenkins, potentially giving them access to other parts of the system.

Affected Systems

The vulnerability affects the Jenkins Project’s SCM‑Manager Plugin, specifically versions 1.11.1 and older. No other vendors or products are listed.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no current known widespread exploitation. The CVSS score of 4.2 reflects limited severity. Because the flaw is a CSRF attack, exploitation requires the attacker to convince an authenticated Jenkins user to perform a request; this is inferred from the description. Once triggered, the attacker can obtain credential IDs and use them to connect to an arbitrary URL, enabling credential theft or lateral movement. The lack of publicly available exploitation knowledge suggests the risk remains primarily limited to the potential for credential compromise if an authenticated session is available.

Generated by OpenCVE AI on August 6, 2026 at 18:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SCM‑Manager Plugin to version 1.11.2 or later.
  • If an upgrade is not immediately possible, restrict the usage of external URL connections from Jenkins or block outbound traffic to unknown hosts using firewall rules.
  • Review credential storage and access logs to detect any unauthorized credential usage and revoke compromised credentials promptly.

Generated by OpenCVE AI on August 6, 2026 at 18:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Scm-manager Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Scm-manager Plugin

Thu, 06 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Title CSRF in Jenkins SCM‑Manager Plugin Enables Credential Theft

Thu, 06 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title CSRF in Jenkins SCM‑Manager Plugin Enables Credential Theft
Weaknesses CWE-352

Wed, 05 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
References

Subscriptions

Jenkins Project Jenkins Scm-manager Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-08-06T14:59:33.694Z

Reserved: 2026-08-04T14:13:20.602Z

Link: CVE-2026-70434

cve-icon Vulnrichment

Updated: 2026-08-06T14:59:19.219Z

cve-icon NVD

Status : Received

Published: 2026-08-05T18:17:13.137

Modified: 2026-08-06T16:16:52.570

Link: CVE-2026-70434

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:38Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)