๐Ÿ” CVE Alert

CVE-2026-70435

MEDIUM 4.2
CVSS Score
4.2
EPSS Score
0.1%
EPSS Percentile
4th

A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Vendor jenkins project
Product jenkins scm-manager plugin
Published Aug 5, 2026
Last Updated Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for jenkins project jenkins scm-manager plugin

Be the first to know when new medium vulnerabilities affecting jenkins project jenkins scm-manager plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Jenkins Project / Jenkins SCM-Manager Plugin
0 โ‰ค 1.11.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
jenkins.io: https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3888