CVE-2026-92130: Jenkins Project Jenkins Pipeline: Multibranch Plugin
Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
Affected products
- Jenkins Project Jenkins Pipeline: Multibranch Plugin: up to and including 841.vec5b_9e1806ec
Published 2026-09-16. Last modified 2026-09-18.