Description
A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Published: 2026-08-05
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Jenkins SCM-Manager Plugin 1.11.1 and earlier lacks a required permission check. An attacker who has the Overall/Read permission can instruct the plugin to connect to an arbitrary URL using an attacker‑specified credential ID that the attacker has obtained by other means. The plugin then uses that credential ID to access the target URL, effectively capturing credentials that are stored in Jenkins. The result is that the attacker can exfiltrate stored credentials and potentially gain further access to the Jenkins environment or downstream systems. The vulnerability is thus an improper access control flaw that can lead to credential theft.

Affected Systems

This issue affects the Jenkins Project's SCM-Manager Plugin versions 1.11.1 and earlier. All Jenkins installations that run this plugin version are potentially exposed. The vulnerability does not affect newer releases of the plugin. The affected product is Jenkins SCM-Manager Plugin, revision ≤ 1.11.1.

Risk and Exploitability

The EPSS score indicates a very low probability of exploitation (<1%) and the vulnerability is not listed in the CISA KEV catalog, so the formal risk metrics are unclear. The CVSS score of 4.2 indicates a moderate risk level. However, because the flaw permits credential leakage without additional privileges, the potential impact is still significant in environments where credentials are critical. The likely attack vector is through the Jenkins web interface or API, where an authorized but read‑only user can trigger the vulnerable behavior.

Generated by OpenCVE AI on August 6, 2026 at 18:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SCM-Manager Plugin to version 1.11.2 or later, which includes a proper permission check for credential usage.
  • If an upgrade is not immediately possible, restrict Overall/Read permissions to trusted users only, and review team roles for unnecessary read access.
  • Disable the SCM-Manager Plugin or remove it from Jenkins instances that do not require SCM access, limiting the attack surface.

Generated by OpenCVE AI on August 6, 2026 at 18:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Scm-manager Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Scm-manager Plugin

Thu, 06 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Read‑Only Access Allows Credential Exfiltration in Jenkins SCM-Manager Plugin

Thu, 06 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Enables Credential Capture via SCM-Manager Plugin
Weaknesses CWE-284

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Enables Credential Capture via SCM-Manager Plugin
Weaknesses CWE-284

Wed, 05 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
References

Subscriptions

Jenkins Project Jenkins Scm-manager Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-08-06T14:57:47.318Z

Reserved: 2026-08-04T14:13:20.602Z

Link: CVE-2026-70435

cve-icon Vulnrichment

Updated: 2026-08-06T14:57:30.787Z

cve-icon NVD

Status : Received

Published: 2026-08-05T18:17:13.237

Modified: 2026-08-06T16:16:52.730

Link: CVE-2026-70435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:36Z

Weaknesses