Jenkins SCM-Manager Plugin Vulnerability Exposes User Credentials
CVE-2026-70435
Currently unrated
What is CVE-2026-70435?
The Jenkins SCM-Manager Plugin prior to version 1.11.1 contains a vulnerability that allows users with Overall/Read permissions to connect to arbitrary URLs. Attackers can leverage this flaw to capture credentials stored within Jenkins by using credentials IDs obtained through unauthorized means. This exposure poses a serious risk to the integrity of user data and the security of the Jenkins environment.
Affected Version(s)
Jenkins SCM-Manager Plugin 0 <= 1.11.1