CVE-2026-42522 Details
Description
A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.
A vulnerability exists in the GitHub Branch Source Plugin for Jenkins, specifically in versions through 1967.vdea_d580c1a_b_a_. The issue arises from a missing permission check that allows attackers with Overall/Read permission to connect to a URL of their choice using GitHub App credentials. This vulnerability could be exploited to manipulate GitHub integrations or access resources in a way that could harm the Jenkins environment or its users.
Users of the GitHub Branch Source Plugin should update to version 1967.1969.v205fd594c821, which requires Overall/Manage permission to perform the connection test, thereby addressing the vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.jenkins.io/security/advisory/2026-04-29/#SECURITY-3702 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| jenkins github branch source | <= 1967.vdea_d580c1a_b_a |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 6, 2026 | Initial Analysis | [email protected] |
| Apr 29, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | New CVE Received | [email protected] |