AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70442

MEDIUM · CVSS 4.3 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Jenkins Google Chat Notification Plugin versions up to 166.ve6b_de280f2e8 are vulnerable due to improper context settings for credential lookups, enabling attackers with Item/Configure permissions to access unauthorized credentials. This could lead to unauthorized access to sensitive information and potential exploitation of other systems. Organizations using this plugin should prioritize remediation to mitigate risks associated with credential exposure.

CVE
CVE-2026-70442
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%
Jenkins

Original NVD Description

Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use.