Information Disclosure in Jenkins Gradle Plugin by CloudBees
CVE-2026-92132
Currently unrated
What is CVE-2026-92132?
The Jenkins Gradle Plugin is susceptible to an information disclosure vulnerability that allows attackers to exploit build logs. Specifically, when the plugin requests build scan data from a build scan link, it does so without regard to a configured Develocity server URL. This flaw enables an attacker who can control the build log to capture the Develocity access key from the global configuration, potentially compromising security. Organizations using the affected versions should review their setups and apply necessary mitigations as detailed in the Jenkins Security Advisory.
Affected Version(s)
Jenkins Gradle Plugin 0 <= 2.19.1252.v15196b_5a_6e10