CVE-2026-70434: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70434?
CVE-2026-70434 has a risk rating of 56.
How do I fix CVE-2026-70434?
To mitigate CVE-2026-70434, you should upgrade the Jenkins SCM-Manager Plugin to version 1.11.2 or later.
What type of vulnerability is CVE-2026-70434?
CVE-2026-70434 is classified as a cross-site request forgery (CSRF) vulnerability.
What can attackers achieve with CVE-2026-70434?
Attackers can exploit CVE-2026-70434 to connect to an attacker-specified URL using attacker-specified credential IDs to capture Jenkins credentials.
Is my Jenkins instance vulnerable to CVE-2026-70434?
If you are using Jenkins SCM-Manager Plugin version 1.11.1 or earlier, your instance is vulnerable to CVE-2026-70434.