CVE-2026-42520: Path Traversal
Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42520?
CVE-2026-42520 is rated as a critical severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2026-42520?
To fix CVE-2026-42520, update the Jenkins Credentials Binding Plugin to a version later than 719.v80e905ef14eb_.
What type of attack does CVE-2026-42520 enable?
CVE-2026-42520 enables attackers to write files to arbitrary locations on the node filesystem, potentially leading to remote code execution.
Which versions of the Jenkins Credentials Binding Plugin are affected by CVE-2026-42520?
Versions of the Jenkins Credentials Binding Plugin up to and including 719.v80e905ef14eb_ are affected by CVE-2026-42520.
Who is impacted by CVE-2026-42520?
Any Jenkins user utilizing the Credentials Binding Plugin version 719.v80e905ef14eb_ or earlier is impacted by CVE-2026-42520.