Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Muhamad Billy Sakti Baraja

#35645of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2026-35914
7.5
2026-04-29
Jenkins · Credentials Binding Plugin · CVE-2026-42520
**Name of the Vulnerable Software and Affected Versions** Jenkins Credentials Binding Plugin versions prior to 719.v80e905ef14eb **Description** Insufficient sanitization of file names for file and zip file credentials allows attackers who can provide credentials to a job to write files to arbitrary locations on the node filesystem. This can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node. **Recommendations** Update the plugin to a version later than 719.v80e905ef14eb .