PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-92133 Jenkins Project CVE debrief

CVE-2026-92133 debrief: The Jenkins GitLab Plugin vulnerability allows unauthorized access to GitLab API token credentials due to improper caching. This affects Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier. Defenders should verify and restrict access to plugin configurations, especially in multi-user environments. The vulnerability enables attackers with Item/Configure permission to access GitLab API token credentials they are not entitled to use. This issue arises from the plugin caching the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials are ...

Vendor
Jenkins Project
Product
Jenkins GitLab Plugin
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-18
Advisory published
2026-09-16
Advisory updated
2026-09-18

Who should care

Defenders responsible for Jenkins and GitLab Plugin configurations, especially in environments with multiple users and projects, should assess exposure and verify access controls. Operators managing Jenkins instances, security teams reviewing plugin vulnerabilities, and platform administrators overseeing GitLab integrations should review and restrict access to plugin configurations to prevent unauthorized access to GitLab API token credentials. Those who

Why it matters

CVE-2026-92133 allows attackers with Item/Configure permission to access GitLab API token credentials they should not use, due to improper caching of GitLab API clients in Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier. Defenders should verify and restrict access to plugin configurations, especially in multi-user environments.

  • Potential unauthorized access to GitLab API token credentials
  • Possible lateral movement within Jenkins environments
  • Required verification of Jenkins GitLab Plugin configurations and access controls
  • Need for timely updates to affected plugin versions

Technical summary

The Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials are resolved. This allows attackers with Item/Configure permission to access GitLab API token credentials they are not entitled to use. The vulnerability arises from improper caching of GitLab API clients, enabling unauthorized access to credentials. Defenders should prioritize verifying and restricting access to Jenkins GitLab Plugin configurations, especially in environments with multiple users and projects. The issue ...

Defensive priority

Defenders should prioritize verifying and restricting access to Jenkins GitLab Plugin configurations, especially in environments with multiple users and projects.

Recommended defensive actions

  • Verify and restrict access to Jenkins GitLab Plugin configurations
  • Update Jenkins GitLab Plugin to a version that fixes the vulnerability
  • Monitor Jenkins GitLab Plugin usage and credentials access
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier. The plugin caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials are resolved.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-92133 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-92133

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-92133 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92133

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.