Description
Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
Published: 2026-09-16
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Credential Disclosure
Action: Immediate Patch
AI Analysis

Impact

The Multibranch Plugin incorrectly sets the context for credentials lookup during the resolveScm Pipeline step, allowing an attacker with Item/Configure permission on a job to read and capture credentials they are not entitled to. This results in non‑privileged users gaining exposure to sensitive credentials, which can lead to further compromise of downstream systems. The weakness is classified as CWE‑863, reflecting an authorization bypass that permits unauthorized access to protected resources.

Affected Systems

Jenkins Pipeline: Multibranch Plugin versions prior to 841.vec5b_9e1806ec in the Jenkins Project are affected. Any Jenkins instance that uses these plugin versions is vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 3.1, indicating low severity, and an EPSS of less than 1 %, suggesting a low likelihood of exploitation. It is not currently listed in CISA’s KEV catalog. Exploitation requires that the attacker have Item/Configure rights on a job and can run Pipeline steps that invoke resolveScm; the attack surface is therefore limited to trusted or compromised users with job configuration privileges. The impact is credential disclosure only, but the exposed credentials could be used to attack other services or systems.

Generated by OpenCVE AI on September 18, 2026 at 06:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Multibranch Plugin to a fixed version (any release after 841.vec5b_9e1806ec).
  • Restrict Item/Configure permissions so that only trusted users can configure pipelines.
  • Audit existing pipelines to ensure resolveScm steps no longer expose credentials.

Generated by OpenCVE AI on September 18, 2026 at 06:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Jenkins Multibranch Plugin Credential Disclosure via Improper Context Setting

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Pipeline Multibranch Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Pipeline Multibranch Plugin

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
References

Subscriptions

Jenkins Project Jenkins Pipeline Multibranch Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-16T19:45:41.178Z

Reserved: 2026-09-15T16:29:44.794Z

Link: CVE-2026-92130

cve-icon Vulnrichment

Updated: 2026-09-16T19:45:35.152Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:15.017

Modified: 2026-09-18T13:46:13.937

Link: CVE-2026-92130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:45:04Z

Weaknesses