Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unsanitized File Names Allow Arbitrary File Write in Jenkins Credentials Binding Plugin |
Wed, 17 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary File Write Leading to Remote Code Execution via Unsanitized Credential Filenames |
Tue, 16 Jun 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary File Write Leading to Remote Code Execution via Unsanitized Credential Filenames |
Fri, 29 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Jenkins Credentials Binding Plugin Arbitrary File Write Allows Remote Code Execution |
Thu, 28 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins credentials Binding |
|
| CPEs | cpe:2.3:a:jenkins:credentials_binding:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins credentials Binding |
Thu, 28 May 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins Project
Jenkins Project jenkins Credentials Binding Plugin |
|
| Vendors & Products |
Jenkins Project
Jenkins Project jenkins Credentials Binding Plugin |
Wed, 27 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Jenkins Credentials Binding Plugin Arbitrary File Write Allows Remote Code Execution |
Wed, 27 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 | |
| Metrics |
cvssV3_1
|
Wed, 27 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-05-27T18:35:18.817Z
Reserved: 2026-05-26T14:50:46.813Z
Link: CVE-2026-48922
Updated: 2026-05-27T15:34:27.781Z
Status : Analyzed
Published: 2026-05-27T15:16:31.847
Modified: 2026-06-17T10:55:24.203
Link: CVE-2026-48922
No data.
OpenCVE Enrichment
Updated: 2026-06-18T13:00:16Z