CVE-2026-92130: Jenkins Project Jenkins Pipeline: Multibranch Plugin

Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.

Affected products

  • Jenkins Project Jenkins Pipeline: Multibranch Plugin: up to and including 841.vec5b_9e1806ec

Published 2026-09-16. Last modified 2026-09-18.