CVE-2026-70435: Medium severity Jenkins SCM-Manager Plugin vulnerability
A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70435?
CVE-2026-70435 has a risk score of 60, indicating a moderate severity vulnerability.
How do I fix CVE-2026-70435?
To fix CVE-2026-70435, update the Jenkins SCM-Manager Plugin to version 1.11.2 or later where the issue has been addressed.
What is the impact of CVE-2026-70435?
CVE-2026-70435 allows attackers with Overall/Read permission to access sensitive credentials stored in Jenkins.
Who is affected by CVE-2026-70435?
Users of Jenkins SCM-Manager Plugin version 1.11.1 and earlier are affected by CVE-2026-70435.
Can CVE-2026-70435 lead to credential theft?
Yes, CVE-2026-70435 can lead to credential theft by allowing attackers to specify URLs and capture credentials.