Credential Lookup Vulnerability in Jenkins Google Chat Notification Plugin by Jenkins
CVE-2026-70442

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
5 August 2026

What is CVE-2026-70442?

A vulnerability exists in the Jenkins Google Chat Notification Plugin, specifically in versions up to and including 166.ve6b_de280f2e8, which does not properly set the context for credentials lookup. This oversight permits users with Item/Configure permission to gain unauthorized access to and potentially capture sensitive credentials that should be restricted. Such exposure can lead to significant security risks, including unauthorized actions and data breaches within the Jenkins environment.

Affected Version(s)

Jenkins Google Chat Notification Plugin 0 <= 166.ve6b_de280f2e8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.