cbcvebase.
CVE-2026-48922
published 2026-05-27

CVE-2026-48922: Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing attackers…

high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.

Affected

24 ranges
VendorProductVersion rangeFixed in
jenkinsactive_directory
jenkinsactive_directory_plugin
jenkinsappspider
jenkinsappspider_plugin
jenkinsbitbucket_oauth
jenkinsbitbucket_oauth_plugin
jenkinscredentials_binding< 725.ve52b_2328a_fde725.ve52b_2328a_fde
jenkinscredentials_binding
jenkinscredentials_binding_plugin
jenkinsemail_extension
jenkinsemail_extension_plugin
jenkinsgithub_integration
jenkinsgithub_integration_plugin
jenkinsgroovy_libraries
jenkinsgroovy_libraries_plugin
jenkinsjob_import
jenkinsjob_import_plugin
jenkinsldap
jenkinsldap_plugin
jenkinsldap_referrals_in_active_directory
jenkinsldap_referrals_in_active_directory_plugin
jenkinsmultijob
jenkinsmultijob_plugin
jenkins_projectjenkins_credentials_binding_plugin<= 720.v3f6decef43ea_