CVE-2026-92130: Jenkins Pipeline: Multibranch Plugin vulnerability
Published Sep 16, 2026
·Updated
Jenkins Pipeline: Multibranch Plugin 841.vec5b9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
Affected Software
1 affected component
Jenkins Pipeline: Multibranch Plugin<=841.vec5b_9e1806ec
Event History
Sep 16, 2026
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Item/Configure permission in Jenkins. The issue affects credential lookup performed by the resolveScm Pipeline step.
2
What could an attacker gain through successful exploitation?
An attacker with the required permission could access and capture credentials that they are not otherwise entitled to use.
3
Which plugin releases are affected?
Jenkins Pipeline: Multibranch Plugin version 841.vec5b_9e1806ec and earlier is affected.