Description
Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials are resolved, allowing attackers with Item/Configure permission to access GitLab API token credentials they are not entitled to use.
Published: 2026-09-16
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality compromise through unauthorized access to GitLab API token credentials
Action: Update Plugin
AI Analysis

Impact

Jenkins GitLab Plugin versions through 1.2149.vcfc32c82b_f7f store a GitLab API client in a cache whose key is derived only from the credentials identifier, ignoring the folder context. This design flaw lets an attacker who has Item/Configure permission on a Jenkins item obtain the API token associated with another credentials entry they are not authorized to use. The exposed token permits the attacker to authenticate as the original credential holder and access the victim’s GitLab resources, potentially exposing repositories, secrets and other sensitive data. No arbitrary code execution or denial of service is reported; the core risk is the disclosure of privileged credentials.

Affected Systems

The vulnerability affects the Jenkins Project: Jenkins GitLab Plugin, specifically all releases up to and including 1.2149.vcfc32c82b_f7f. Users deploying older versions of this plugin are susceptible until an update containing the cache key fix is installed.

Risk and Exploitability

With a CVSS score of 5.4 the risk assessment is medium. The EPSS score of less than 1% indicates a low probability that the vulnerability is actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to possess Item/Configure rights on a Jenkins project, a permission that should be restricted to administrators or trusted users. Once those rights are attained, the attacker can read the compromised credentials via the Jenkins UI or API.

Generated by OpenCVE AI on September 18, 2026 at 05:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Jenkins GitLab Plugin to a version newer than 1.2149.vcfc32c82b_f7f that corrects the cache key logic.
  • Ensure that only trusted administrators have Item/Configure permissions on Jenkins items to limit the ability to retrieve unauthorized credentials.
  • Review all GitLab API token credentials for proper access controls and remove any that are no longer needed or that may be exposed.

Generated by OpenCVE AI on September 18, 2026 at 05:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title GitLab API Token Exposure via Jenkins GitLab Plugin Cache

Thu, 17 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Gitlab Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Gitlab Plugin

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-522
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials are resolved, allowing attackers with Item/Configure permission to access GitLab API token credentials they are not entitled to use.
References

Subscriptions

Jenkins Project Jenkins Gitlab Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-16T19:10:56.633Z

Reserved: 2026-09-15T16:29:44.795Z

Link: CVE-2026-92133

cve-icon Vulnrichment

Updated: 2026-09-16T19:10:50.022Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:15.300

Modified: 2026-09-18T13:46:13.937

Link: CVE-2026-92133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:15:03Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials