CVE-2026-70436
Summary
| CVE | CVE-2026-70436 |
| State | PUBLISHED |
| Assigner | jenkins |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-05 18:17:13 UTC |
| Updated | 2026-08-05 18:17:13 UTC |
| Description | Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in workspaces they are not authorized to access. |
Vendor Declared Affected Products
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.