CVE-2026-92133: Jenkins Project Jenkins GitLab Plugin
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials are resolved, allowing attackers with Item/Configure permission to access GitLab API token credentials they are not entitled to use.
Affected products
- Jenkins Project Jenkins GitLab Plugin: up to and including 1.2149.vcfc32c82b_f7f
Published 2026-09-16. Last modified 2026-09-18.