Information Disclosure in Jenkins Gradle Plugin by CloudBees
CVE-2026-92132

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92132?

The Jenkins Gradle Plugin is susceptible to an information disclosure vulnerability that allows attackers to exploit build logs. Specifically, when the plugin requests build scan data from a build scan link, it does so without regard to a configured Develocity server URL. This flaw enables an attacker who can control the build log to capture the Develocity access key from the global configuration, potentially compromising security. Organizations using the affected versions should review their setups and apply necessary mitigations as detailed in the Jenkins Security Advisory.

Affected Version(s)

Jenkins Gradle Plugin 0 <= 2.19.1252.v15196b_5a_6e10

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.