Record summary

CVE-2026-42520 has a selected CVSS score of 7.5 (high).

Description

Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 29, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 719.v80e905ef14eb_affected

org.jenkins-ci.plugins:credentials-binding

Browse Maven / org.jenkins-ci.plugins:credentials-binding
GitHub AdvisoryBefore 720.v3f6decef43ea · Fixed in 720.v3f6decef43eaaffected

References

3