CVE-2026-70437 Details
Description
Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token.
A vulnerability exists in the Webhook Secret Credentials Provider Plugin for Jenkins, specifically in versions through 16.v0cfa_f0215cf5. The plugin fails to use a constant-time comparison function when verifying the equality of the provided and expected webhook bearer tokens. This flaw could enable attackers to employ statistical methods to deduce a valid webhook bearer token.
Users of the Webhook Secret Credentials Provider Plugin should update to version 32.v09c9b_522f0a_8, which includes the necessary fix. For Jenkins core, update to version 2.576 or LTS version 2.568.2.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3918 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-208 | Observable Timing Discrepancy | CISA-ADP |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |