AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70436

MEDIUM · CVSS 4.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The External Workspace Manager Plugin in Jenkins versions 1.4.1 and earlier lacks proper permission checks, enabling users with Overall/Read permissions to access unauthorized files in externally-managed workspaces. This vulnerability could lead to sensitive information disclosure, making it critical for Jenkins administrators and organizations using this plugin to prioritize updates to version 1.4.2 or later to mitigate potential data breaches.

CVE
CVE-2026-70436
Severity
MEDIUM
CVSS
4.3
EPSS
0.22%
Jenkins

Original NVD Description

Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in workspaces they are not authorized to access.