Authentication Bypass in Jenkins GitLab Plugin by Jenkins
CVE-2026-92133

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92133?

The Jenkins GitLab Plugin contains a vulnerability that allows attackers with Item/Configure permissions to access GitLab API token credentials. The vulnerability arises from the caching mechanism, which improperly derives the cache key using only the credentials ID, failing to consider the associated folder. This exploit enables unauthorized users to retrieve sensitive API token credentials, potentially compromising the security of GitLab integrations.

Affected Version(s)

Jenkins GitLab Plugin 0 <= 1.2149.vcfc32c82b_f7f

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.