Webhook Secret Credentials Provider Plugin Vulnerable in Jenkins
CVE-2026-70437
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-70437?
The Webhook Secret Credentials Provider Plugin for Jenkins fails to perform token validation using a constant-time comparison. This oversight allows potential attackers to exploit timing discrepancies, enabling them to utilize statistical methods to derive valid webhook bearer tokens. Organizations using this plugin may face risks related to unauthorized access and compromised webhook communications.
Affected Version(s)
Jenkins Webhook Secret Credentials Provider Plugin 0 <= 16.v0cfa_f0215cf5