CVE-2026-48922: Input Validation
Jenkins Credentials Binding Plugin 720.v3f6decef43ea and earlier does not properly sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48922?
CVE-2026-48922 has a high severity rating of 7.5 according to the CVSS 3.1 metrics.
How do I fix CVE-2026-48922?
To fix CVE-2026-48922, upgrade to Jenkins Credentials Binding Plugin version 721.v3f6decef43ea_ or later.
What type of vulnerability is identified by CVE-2026-48922?
CVE-2026-48922 is an input validation vulnerability in the Jenkins Credentials Binding Plugin.
What could be the potential impact of CVE-2026-48922?
The potential impact of CVE-2026-48922 includes the ability for attackers to write files to arbitrary locations on the filesystem, possibly leading to remote code execution.
Which software versions are affected by CVE-2026-48922?
Versions of Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier are affected by CVE-2026-48922.