Feed/CVE-2026-70435
CVE-2026-70435MEDIUMCVSS 4.2

CVE-2026-70435

Published Aug 5, 2026·Updated Aug 6, 2026

NVD Description

A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free