Improper Access Control in Jenkins External Workspace Manager Plugin
CVE-2026-70436
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-70436?
The External Workspace Manager Plugin for Jenkins lacks adequate permission checks in versions 1.4.1 and earlier, exposing sensitive workspace files to unauthorized users. Attackers who have Overall/Read permission may exploit this flaw to gain access to files located in workspaces for which they have no authorization, potentially leading to data exposure or leaks. Proper security measures and updates are crucial for safeguarding sensitive information managed within Jenkins.
Affected Version(s)
Jenkins External Workspace Manager Plugin 0 <= 1.4.1