Authentication Bypass in Jenkins GitLab Plugin by Jenkins
CVE-2026-92133
Currently unrated
What is CVE-2026-92133?
The Jenkins GitLab Plugin contains a vulnerability that allows attackers with Item/Configure permissions to access GitLab API token credentials. The vulnerability arises from the caching mechanism, which improperly derives the cache key using only the credentials ID, failing to consider the associated folder. This exploit enables unauthorized users to retrieve sensitive API token credentials, potentially compromising the security of GitLab integrations.
Affected Version(s)
Jenkins GitLab Plugin 0 <= 1.2149.vcfc32c82b_f7f