github.com
https://github.com/jenkinsci/credentials-binding-plugin CVE-2026-42520
HIGH
Jenkins Credentials Binding Plugin has a path traversal vulnerability
Record summary
CVE-2026-42520 has a selected CVSS score of 7.5 (high).
Description
Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 29, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Jenkins Credentials Binding PluginBrowse Jenkins Project / Jenkins Credentials Binding PluginDefault status: unaffected | CVE List | Through 719.v80e905ef14eb_ | affected |
org.jenkins-ci.plugins:credentials-bindingBrowse Maven / org.jenkins-ci.plugins:credentials-binding | GitHub Advisory | Before 720.v3f6decef43ea · Fixed in 720.v3f6decef43ea | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-42520 Jenkins Security Advisory 2026-04-29Vendor advisory
https://www.jenkins.io/security/advisory/2026-04-29