CVE-2026-92133: Jenkins GitLab Plugin vulnerability

Published Sep 16, 2026
·
Updated

Jenkins GitLab Plugin 1.2149.vcfc32c82bf7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials are resolved, allowing attackers with Item/Configure permission to access GitLab API token credentials they are not entitled to use.

Affected Software

1 affected component
Jenkins GitLab Plugin<=1.2149.vcfc32c82b_f7f

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Jenkins GitLab Plugin to a version that resolves this vulnerability.

    Fixed in 1.2149.vcfc32c82b_f7f
  2. Compensating control

    Restrict Item/Configure permission in Jenkins so that users cannot modify job configuration to trigger access to cached GitLab API token credentials they are not entitled to use.

Event History

Sep 16, 2026
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs Item/Configure permission. They can exploit the issue to access GitLab API token credentials resolved in a different folder, even when they are not otherwise entitled to use those credentials.

2

Which deployments are affected?

Jenkins installations using GitLab Plugin version 1.2149.vcfc32c82b_f7f or earlier are affected. The issue specifically concerns alternative GitLab API token credentials and folder-based credential resolution.

3

How can I tell whether my Jenkins instance is exposed?

Check the installed Jenkins GitLab Plugin version and whether users with Item/Configure permission can configure items in folders. Exposure is relevant where alternative GitLab API token credentials are available through folder-scoped credential resolution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203