CVE-2026-42520
published 2026-04-29CVE-2026-42520: Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to…
PriorityP354high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
0.41%
33.2th percentile
Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | credentials_binding | <= 719.v80e905ef14eb | — |
| jenkins | credentials_binding | — | — |
| jenkins | credentials_binding_plugin | — | — |
| jenkins | github | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source_plugin | — | — |
| jenkins | github_plugin | — | — |
| jenkins | html_publisher | — | — |
| jenkins | html_publisher_plugin | — | — |
| jenkins | matrix_authorization_strategy | — | — |
| jenkins | matrix_authorization_strategy_plugin | — | — |
| jenkins | script_security | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins_project | jenkins_credentials_binding_plugin | <= 719.v80e905ef14eb_ | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Jenkins
Jenkins Security Advisory 2026-04-29
vendor_jenkins·2026-04-29·CVSS 4.3
CVE-2026-42519 [MEDIUM] Jenkins Security Advisory 2026-04-29
Title: Jenkins Security Advisory 2026-04-29
Jenkins Security Advisory 2026-04-29
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Credentials Binding
Plugin
GitHub
Plugin
GitHub Branch Source
Plugin
HTML Publisher
Plugin
Matrix Authorization Strategy
Plugin
Microsoft Entra ID (previously Azure AD)
VulDB
Jenkins Credentials Binding Plugin up to 719.v80e905ef14eb_ privilege escalation (EUVD-2026-26221 / Nessus ID 310885)
vuldb·2026-04-29·CVSS 7.5
CVE-2026-42520 [HIGH] Jenkins Credentials Binding Plugin up to 719.v80e905ef14eb_ privilege escalation (EUVD-2026-26221 / Nessus ID 310885)
A vulnerability marked as critical has been reported in Jenkins Credentials Binding Plugin up to 719.v80e905ef14eb_. The impacted element is an unknown function. Performing a manipulation results in privilege escalation.
This vulnerability is reported as CVE-2026-42520. The attack is possible to be carried out remotely. No exploit exists.
GHSA
Jenkins Credentials Binding Plugin has a path traversal vulnerability
ghsa·2026-04-29
CVE-2026-42520 [HIGH] CWE-22 Jenkins Credentials Binding Plugin has a path traversal vulnerability
Jenkins Credentials Binding Plugin has a path traversal vulnerability
Jenkins Credentials Binding Plugin versions 719.v80e905ef14eb_ and earlier do not sanitize file names for file and zip file credentials.
This allows attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem. If Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node, this can lead to remote code execution.
Credentials Binding Plugin 720.v3f6decef43ea_ sanitizes the file name provided for file and zip file credentials, preventing path traversal.
No detection rules found.
No public exploits indexed.
2026-04-29
Published