Credential Lookup Vulnerability in Jenkins Google Chat Notification Plugin by Jenkins
CVE-2026-70442
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-70442?
A vulnerability exists in the Jenkins Google Chat Notification Plugin, specifically in versions up to and including 166.ve6b_de280f2e8, which does not properly set the context for credentials lookup. This oversight permits users with Item/Configure permission to gain unauthorized access to and potentially capture sensitive credentials that should be restricted. Such exposure can lead to significant security risks, including unauthorized actions and data breaches within the Jenkins environment.
Affected Version(s)
Jenkins Google Chat Notification Plugin 0 <= 166.ve6b_de280f2e8