CVE-2026-42520Disclosure(jenkins / credentials_binding)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch jenkins credentials_binding systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • credentials_binding

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-07)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
credentials_binding

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-29: 1Mentions · 2026-05-07: 2Patch / Workaround · 2026-05-07: 1Technical Details · 2026-04-29: 1Technical Details · 2026-05-07: 204-2905-07
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-291
Disclosure1
2026-05-072
General1Patch1
Full discourse3 posts
  • iototsecnews@iototsecnews
    Patch

    Jenkins プラグインの 7 件の脆弱性が FIX:パス・トラバーサルや蓄積型 XSS の不具合を修正 https://iototsecnews.jp/2026/04/30/jenkins-plugin-updates-fix-path-traversal-and-stored-xss-bugs/ 今回の脆弱性は、主に外部から入力されたデータの処理不備が原因で発生しています。特に深刻な CVE-2026-42520 では、ファイル名のサニタイズ (無害化) が不十分だったため、本来アクセスできない場所にファイルを書き込まれるリスクが生じています。また、CVE-2026-42523 や CVE-2026-42524 では、URL などの情報を画面に表示する際のエスケープ処理が不足しており、悪意のスクリプト実行を許してしまいます。その他にも、CVE-2026-42519 や CVE-2026-42522 のように、適切な権限チェックが行われていない設計上の不備も見つかりました。ご利用のチームは、ご注意ください。 #CVE202642519 #CVE202642521 #CVE202642522 #CVE202642523 #CVE202642524 #CVE202642525 #Jenkins #Plugin #Vulnerability

    Post summary

    The article announces that seven Jenkins plugin vulnerabilities (CVE-2026-42519 to CVE-2026-42525) have been fixed, describing the technical issues but providing no proof of concept or active exploitation reports.

    01000129
    487 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-42520: Jenkins Credentials Binding Path Traversal - What It Means for Your Business and How to Respond https://hubs.li/Q04fNKgp0

    Post summary

    The text introduces CVE-2026-42520 as a Path Traversal issue in Jenkins Credentials Binding and suggests discussing its business impact, but does not provide any exploit details, patches, or evidence of active exploitation.

    0000022
    29 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42520 Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide c… https://www.cve.org/CVERecord?id=CVE-2026-42520

    Post summary

    The Jenkins Credentials Binding Plugin fails to sanitize filenames for file and zip credentials, creating a disclosed vulnerability.

    00000100
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjenkinscredentials_binding-jenkins-

Explore more