CVE-2026-70436: Jenkins Project Jenkins External Workspace Manager Plugin

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in workspaces they are not authorized to access.

Affected products

  • Jenkins Project Jenkins External Workspace Manager Plugin: up to and including 1.4.1

Published 2026-08-05. Last modified 2026-08-31.