Jenkins SCM-Manager Plugin Vulnerability Exposes User Credentials
CVE-2026-70435

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
5 August 2026

What is CVE-2026-70435?

The Jenkins SCM-Manager Plugin prior to version 1.11.1 contains a vulnerability that allows users with Overall/Read permissions to connect to arbitrary URLs. Attackers can leverage this flaw to capture credentials stored within Jenkins by using credentials IDs obtained through unauthorized means. This exposure poses a serious risk to the integrity of user data and the security of the Jenkins environment.

Affected Version(s)

Jenkins SCM-Manager Plugin 0 <= 1.11.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.