CVE-2026-42522 - Jenkins GitHub Branch Source Plugin Permission Bypass Vulnerability
CVE ID :CVE-2026-42522
Published : April 29, 2026, 1:31 p.m. | 43 minutes ago
Description :A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : April 29, 2026, 1:31 p.m. | 43 minutes ago
Description :A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...