PT-2026-35914 · Jenkins · Credentials Binding Plugin+1
Ap4Sh
+3
·
Published
2026-04-29
·
Updated
2026-05-07
·
CVE-2026-42520
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins Credentials Binding Plugin versions prior to 719.v80e905ef14eb
Description
Insufficient sanitization of file names for file and zip file credentials allows attackers who can provide credentials to a job to write files to arbitrary locations on the node filesystem. This can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.
Recommendations
Update the plugin to a version later than 719.v80e905ef14eb .
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Credentials Binding Plugin
Jenkins