Record summary

CVE-2026-70437 has a selected CVSS score of 3.7 (low).

Description

Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Jenkins Webhook Secret Credentials Provider Plugin

Browse Jenkins Project / Jenkins Webhook Secret Credentials Provider Plugin

Default status: unaffected

CVE ListThrough 16.v0cfa_f0215cf5affected

References

2