PT-2026-68271 · Jenkins · External Workspace Manager Plugin

CVE-2026-70436

·

Published

2026-08-05

·

Updated

2026-08-05

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins External Workspace Manager Plugin versions prior to 1.4.2
Description The workspace browser fails to properly validate permissions when granting access to externally-managed workspaces. This allows users with Overall/Read permissions to read files within workspaces for which they lack authorization.
Recommendations Update Jenkins External Workspace Manager Plugin to version 1.4.2 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-70436

Affected Products

External Workspace Manager Plugin