AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70434

MEDIUM · CVSS 4.2 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The SCM-Manager Plugin for Jenkins is vulnerable to a cross-site request forgery (CSRF) flaw that allows attackers to connect to a malicious URL using compromised credentials. This could lead to the unauthorized exposure of sensitive credentials stored within Jenkins. Organizations utilizing affected versions of this plugin should prioritize patching to mitigate the risk of credential theft.

CVE
CVE-2026-70434
Severity
MEDIUM
CVSS
4.2
EPSS
0.09%
Jenkins

Original NVD Description

A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.