CVE-2026-70442: Security vulnerability
Jenkins Google Chat Notification Plugin 166.ve6bde280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jenkins Google Chat Notification Pluginto a version that resolves this vulnerability.Fixed in 166.ve6b_de280f2e8