CVE-2026-70442: Medium severity Jenkins Google Chat Notification Plugin vulnerability
Jenkins Google Chat Notification Plugin 166.ve6bde280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jenkins Google Chat Notification Pluginto a version that resolves this vulnerability.Fixed in 166.ve6b_de280f2e8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70442?
The severity of CVE-2026-70442 is rated at risk level 47.
How do I fix CVE-2026-70442?
To fix CVE-2026-70442, update the Jenkins Google Chat Notification Plugin to version 166.ve6b_de280f2e9 or later.
What permissions are required to exploit CVE-2026-70442?
An attacker needs Item/Configure permission to exploit CVE-2026-70442.
What can attackers access through CVE-2026-70442?
Attackers can access and capture credentials they are not entitled to use due to the vulnerability in CVE-2026-70442.
Which plugin is affected by CVE-2026-70442?
CVE-2026-70442 affects the Jenkins Google Chat Notification Plugin versions 166.ve6b_de280f2e8 and earlier.