PT-2026-93776 · Jenkins · Gitlab Plugin

CVE-2026-92133

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins GitLab Plugin versions prior to 1.2149.vcfc32c82b f7f
Description The plugin caches the GitLab API client for alternative GitLab API token credentials using a cache key based solely on the credentials ID, failing to include the folder where the credentials are resolved. This allows users with Item/Configure permissions to access GitLab API token credentials they are not authorized to use.
Recommendations Update the Jenkins GitLab Plugin to a version later than 1.2149.vcfc32c82b f7f.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92133

Affected Products

Gitlab Plugin