CVE-2026-70437: Low severity Jenkins Jenkins Webhook Secret Credentials Provider Plugin vulnerability
Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfaf0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70437?
CVE-2026-70437 has a risk score of 47, indicating a moderate severity level.
How do I fix CVE-2026-70437?
To fix CVE-2026-70437, upgrade to the latest version of the Jenkins Webhook Secret Credentials Provider Plugin.
What is affected by CVE-2026-70437?
CVE-2026-70437 affects the Jenkins Webhook Secret Credentials Provider Plugin versions 16.v0cfa_f0215cf5 and earlier.
What type of vulnerability is CVE-2026-70437?
CVE-2026-70437 is a cryptographic vulnerability related to improper comparison of bearer tokens.
Can CVE-2026-70437 be exploited remotely?
Yes, CVE-2026-70437 can potentially be exploited by remote attackers using statistical methods to guess valid webhook bearer tokens.