CVE-2026-48922
Description
Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier allows file write via unsanitized file names, potentially leading to RCE on the built-in node.
Vulnerability
Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials [1]. This allows attackers who can configure such credentials for a job to write files to arbitrary locations on the node filesystem [1]. The code path is reachable when a low-privileged user is permitted to define file or zip file credentials used for a job running on the built-in node [1].
Exploitation
An attacker needs the ability to provide file or zip file credentials to a job [1]. This typically requires a low-privileged Jenkins user with permission to configure credentials for a job that runs on the built-in node [1]. The attacker can craft malicious credentials with unsanitized file names to write files outside the intended credential directory [1]. No additional user interaction is required beyond job execution [1].
Impact
Successful exploitation allows the attacker to write files to arbitrary locations on the node filesystem [1]. If the built-in node is the Jenkins controller, this can lead to remote code execution (RCE) on the controller [1]. The impact includes full compromise of the Jenkins instance, as the attacker could write a malicious plugin or modify scripts to gain code execution [1].
Mitigation
As of the advisory publication date (2026-05-27), no fixed version has been released [1]. Administrators should ensure that only trusted users have permission to configure file or zip file credentials, especially for jobs on the built-in node [1]. They should also consider restricting low-privileged users from creating such credentials until a fix is available [1]. This vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=720.v3f6decef43ea_+ 1 more
- (no CPE)range: <=720.v3f6decef43ea_
- (no CPE)range: <= 720.v3f6decef43ea_
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
1- Jenkins Security Advisory 2026-05-27Jenkins Security Advisories · May 27, 2026