CVE-2026-70437
Received Received - Intake

Jenkins Webhook Secret Credentials Provider Plugin Bearer Token Comparison Weakness

Vulnerability report for CVE-2026-70437, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Jenkins Project

Description

Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jenkinsci webhook_secret_credentials_provider_plugin to 16.v0cfa_f0215cf5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Jenkins Webhook Secret Credentials Provider Plugin versions 16.v0cfa_f0215cf5 and earlier have a security flaw where the comparison of webhook bearer tokens is not done using a constant-time function. This could allow attackers to use timing analysis to guess a valid token.

Detection Guidance

This vulnerability involves a timing attack due to non-constant-time comparison of webhook bearer tokens in Jenkins Webhook Secret Credentials Provider Plugin. Detection requires checking plugin versions and analyzing network traffic for timing discrepancies during token validation.

Impact Analysis

An attacker could exploit this to gain unauthorized access to Jenkins webhooks by guessing valid bearer tokens through timing attacks, potentially leading to data breaches or unauthorized actions in the system.

Compliance Impact

This vulnerability could potentially expose webhook bearer tokens, which may lead to unauthorized access to sensitive data. If exploited, it might violate data protection requirements under GDPR or HIPAA by enabling unauthorized disclosure of personal or health information.

Mitigation Strategies

Update Jenkins Webhook Secret Credentials Provider Plugin to the latest version to ensure it uses a constant-time comparison function for webhook bearer token validation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-70437. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart