Description
Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use.
Published: 2026-08-05
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Jenkins Google Chat Notification Plugin, in versions up to 166.ve6b_de280f2e8, fails to establish the correct context during a credentials lookup. As a result, any user who possesses the Item/Configure permission on a given Jenkins item can retrieve credentials that they should not have access to. This flaw effectively exposes sensitive authentication material, enabling an attacker to re‑use or abuse these credentials for unauthorized access to other systems or services that rely on them.

Affected Systems

The vulnerability applies to Jenkins Project’s Google Chat Notification Plugin versions up to and including 166.ve6b_de280f2e8. Any Jenkins instance that includes this plugin within its configuration is potentially impacted.

Risk and Exploitability

Although no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the flaw presents a moderate to high risk because it allows credential theft from privileged configuration users. The CVSS score of 4.3 reflects a moderate severity. The attack can be carried out by any attacker who has Item/Configure permissions, which is typically granted to users with a degree of trust within the Jenkins organization. Because the vulnerability does not require external network access or elevated privileges beyond those permissions, it can be exploited internally by malicious or compromised accounts with sufficient Jenkins configuration rights.

Generated by OpenCVE AI on August 5, 2026 at 23:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Google Chat Notification Plugin to a version newer than 166.ve6b_de280f2e8. This resolves the context handling issue that permits unauthorized credential retrieval.
  • If an upgrade is not immediately possible, remove the plugin from the Jenkins environment until a fixed version is available. Eliminating the plugin eliminates the exploitation surface.
  • Restrict the Item/Configure permission to only trusted or minimally privileged users, ensuring that only those who truly require configuration access can potentially read credentials.

Generated by OpenCVE AI on August 5, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Google Chat Notification Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Google Chat Notification Plugin

Thu, 06 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Jenkins Google Chat Notification Plugin Credential Disclosure Vulnerability

Wed, 05 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Google Chat Notification Plugin Allows Privileged Users to Retrieve Unauthorized Credentials
Weaknesses CWE-284

Wed, 05 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Google Chat Notification Plugin Allows Privileged Users to Retrieve Unauthorized Credentials
Weaknesses CWE-284
CWE-285
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use.
References

Subscriptions

Jenkins Project Jenkins Google Chat Notification Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-08-05T19:38:47.858Z

Reserved: 2026-08-04T14:13:20.603Z

Link: CVE-2026-70442

cve-icon Vulnrichment

Updated: 2026-08-05T19:38:33.364Z

cve-icon NVD

Status : Received

Published: 2026-08-05T18:17:14.030

Modified: 2026-08-05T20:17:15.513

Link: CVE-2026-70442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:26Z

Weaknesses