Description
Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in workspaces they are not authorized to access.
Published: 2026-08-05
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Jenkins External Workspace Manager Plugin versions 1.4.1 and earlier fail to perform a suitable permission check when users browse externally‑managed workspaces. Attackers who possess only the permissive Overall/Read role can view the full contents of workspaces that they should not be able to access, exposing potentially sensitive build artifacts or configuration files.

Affected Systems

The vulnerability affects the Jenkins Project’s External Workspace Manager Plugin, specifically versions 1.4.0 and earlier, which perform no permission verification, and version 1.4.1, which implements an improper check. Any Jenkins installation that has this plugin installed at or below 1.4.1 is susceptible to the flaw.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score of 4.3 signals a moderate severity. The vulnerability arises because any user who has the broad Overall/Read permission can access externally‑managed workspaces through the workspace browser without a proper authorization check. As a result, the attack vector is local to the Jenkins instance; no additional credentials or network traversal are required beyond an existing read role. In environments where the Overall/Read permission is granted to many users and external workspaces contain sensitive artefacts, the risk of unauthorized data disclosure is significant.

Generated by OpenCVE AI on August 6, 2026 at 18:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the External Workspace Manager Plugin to a version newer than 1.4.1 or apply the vendor‑supplied fix.
  • Restrict the Overall/Read permission to trusted users and consider applying the principle of least privilege for workspace access.
  • If an upgrade is not immediately possible, disable or remove the external workspace browser feature to block unauthenticated browsing.

Generated by OpenCVE AI on August 6, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Permission Check Bypass in Jenkins External Workspace Manager Plugin Allows Unauthorized File Disclosure

Thu, 06 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Permission Check Bypass in Jenkins External Workspace Manager Plugin Allows Unauthorized Workspace File Disclosure
Weaknesses CWE-200
CWE-285

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Permission Check Bypass in Jenkins External Workspace Manager Plugin Allows Unauthorized Workspace File Disclosure
First Time appeared Jenkins Project
Jenkins Project jenkins External Workspace Manager Plugin
Weaknesses CWE-200
CWE-285
Vendors & Products Jenkins Project
Jenkins Project jenkins External Workspace Manager Plugin

Wed, 05 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in workspaces they are not authorized to access.
References

Subscriptions

Jenkins Project Jenkins External Workspace Manager Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-08-06T14:56:37.701Z

Reserved: 2026-08-04T14:13:20.602Z

Link: CVE-2026-70436

cve-icon Vulnrichment

Updated: 2026-08-06T14:56:14.435Z

cve-icon NVD

Status : Received

Published: 2026-08-05T18:17:13.350

Modified: 2026-08-06T16:16:52.887

Link: CVE-2026-70436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T18:30:04Z

Weaknesses