Jenkins Pipeline Multibranch Plugin Vulnerability Exposes Credentials
CVE-2026-92130
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-92130?
The Jenkins Pipeline: Multibranch Plugin prior to version 841.vec5b_9e1806ec fails to establish a secure context for credential lookup during the resolveScm Pipeline step. This oversight enables an attacker that has Item/Configure permissions to gain unauthorized access to sensitive credentials, potentially exposing them to malicious activities.
Affected Version(s)
Jenkins Pipeline: Multibranch Plugin 0 <= 841.vec5b_9e1806ec