AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-70437

LOW · CVSS 3.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Jenkins Webhook Secret Credentials Provider Plugin versions 16.v0cfa_f0215cf5 and earlier are vulnerable due to the lack of a constant-time comparison function when validating webhook bearer tokens. This flaw could allow attackers to exploit timing discrepancies to infer valid tokens, potentially compromising the integrity of webhook communications. Organizations using this plugin should prioritize remediation to safeguard against unauthorized access and potential exploitation.

CVE
CVE-2026-70437
Severity
LOW
CVSS
3.7
EPSS
0.17%
Jenkins F5

Original NVD Description

Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token.