Description
Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration, allowing attackers able to control the build log to capture the Develocity access key configured in the global configuration by having Jenkins connect to an attacker-specified URL.
Published: 2026-09-16
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure - Develocity Access Key
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows a malicious actor who controls the content of a Jenkins build log to insert a Develocity build scan link that points to an attacker‑specified URL. The Jenkins Gradle Plugin, when processing the log, connects to this URL and retrieves the Develocity access key that is stored in Jenkins’ global configuration, even though a Develocity server URL has already been configured. This causes the accidental export of a privileged key and therefore a loss of confidentiality for the build environment. The weakness is an Improper Neutralization of Special Elements Used in an Argument, shown in the CWE list.

Affected Systems

Jenkins Gradle Plugin versions 2.19.1252 and prior. Any Jenkins installation that uses these plugin versions and has an active global Develocity configuration is affected.

Risk and Exploitability

The CVSS score of 5.4 reflects moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. The likely attack vector is that an adversary must already be able to influence the content that is written to the build log, which could be achieved by injecting malicious code into a build or by exploiting a build‑execution privilege. Once the log contains a malicious link, the vulnerable plugin will reach out and expose the Develocity access key because it does not verify that the target URL matches the configured Develocity server URL.

Generated by OpenCVE AI on September 18, 2026 at 06:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Jenkins Gradle Plugin to a version newer than 2.19.1252.
  • Configure the plugin or Jenkins instance to disallow or filter outgoing HTTP(S) requests made from build logs, ensuring only the configured Develocity server URL is used.
  • Restrict write access to build logs so that only trusted users or systems can inject arbitrary URLs into the log.
  • Consider applying additional network controls or scanning tooling to detect unintended outgoing connections from Jenkins build processes.

Generated by OpenCVE AI on September 18, 2026 at 06:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Develocity Access Key Disclosure via Build Log in Jenkins Gradle Plugin

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Gradle Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Gradle Plugin

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-74
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration, allowing attackers able to control the build log to capture the Develocity access key configured in the global configuration by having Jenkins connect to an attacker-specified URL.
References

Subscriptions

Jenkins Project Jenkins Gradle Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-16T19:44:18.165Z

Reserved: 2026-09-15T16:29:44.795Z

Link: CVE-2026-92132

cve-icon Vulnrichment

Updated: 2026-09-16T19:43:52.619Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:15.210

Modified: 2026-09-18T13:46:13.937

Link: CVE-2026-92132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:45:04Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')