PT-2026-35914 · Jenkins · Credentials Binding Plugin+1

Ap4Sh

+3

·

Published

2026-04-29

·

Updated

2026-05-07

·

CVE-2026-42520

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Credentials Binding Plugin versions prior to 719.v80e905ef14eb
Description Insufficient sanitization of file names for file and zip file credentials allows attackers who can provide credentials to a job to write files to arbitrary locations on the node filesystem. This can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.
Recommendations Update the plugin to a version later than 719.v80e905ef14eb .

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42520
GHSA-P2RF-WPXJ-MX2G

Affected Products

Credentials Binding Plugin
Jenkins