{"id":"GHSA-wg26-8wmj-cf9p","summary":"Jenkins GitHub Branch Source Plugin: Missing permissions check allows attackers to perform a connection test","details":"Jenkins GitHub Branch Source Plugin versions 1967.vdea_d580c1a_b_a_ and earlier do not perform a permission check in a method implementing form validation.\n\nThis allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.\n\nGitHub Branch Source Plugin 1967.1969.v205fd594c821 requires Overall/Manage permission to perform the connection test.","aliases":["CVE-2026-42522"],"modified":"2026-05-06T23:11:24.107078Z","published":"2026-04-29T15:30:38Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-06T22:48:34Z","nvd_published_at":"2026-04-29T14:16:19Z","cwe_ids":["CWE-862"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42522"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2026-04-29/#SECURITY-3702"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:github-branch-source","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/github-branch-source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1967.1969.v205fd594c821"}]}],"versions":["0.1-beta-1","0.1-beta-2","0.1-beta-3","0.1-beta-4","1.0","1.1","1.10","1.10.1","1.2","1.3","1.4","1.4-beta-1","1.5","1.6","1.7","1.8","1.8.1","1.9","1577.v83564088883f","1583.v18d333ef7379","1598.v91207e9f9b_4a_","1599.v9fb_798a_a_7c4f","1602.vfe89fe441b_36","1619.v962f131fa_c15","1628.vb_2f51293cb_78","1637.vd833b_7ca_7654","1656.v77eddb_b_e95df","1677.v731f745ea_0cf","1687.v7618247e672d","1694.vd46793a_c4a_57","1695.v88de84e9f6b_9","1696.v3a_7603564d04","1701.v00cc8184df93","1703.vd5a_2b_29c6cdc","1725.vd391eef681a_e","1728.v859147241f49","1730.vff97c8a_1f804","1732.v3f1889a_c475b_","1734.v8a_ed3a_653490","1740.v51d5810e9e8c","1741.va_3028eb_9fd21","1748.v6b_61a_1dc35b_4","1750.v6b_fb_8df8f985","1751.v90e17c48a_6a_c","1752.vc201a_0235d80","1755.vcdb_d136f3b_25","1758.v048414714f5d","1767.va_7d01ea_c7256","1771.v59b_6a_fa_1b_89e","1772.va_69eda_d018d4","1781.va_153cda_09d1b_","1785.v99802b_69816c","1787.v8b_8cd49a_f8f1","1789.v5b_0c0cea_18c3","1790.v5a_7859812c8d","1793.v1831e9c68d77","1797.v86fdb_4d57d43","1803.v98e3d8a_c8169","1807.v50351eb_7dd13","1809.v088b_5f22c768","1810.v913311241fa_9","1815.v9152b_2ff7a_1b_","1822.v9eec8e5e69e3","1824.v046257273408","1833.v77b_6542df5a_8","1834.v857721ea_74c6","1844.v4a_9883d49126","1848.v42f74f7f4500","1862.v1a_fc22a_d3788","1864.v411feec5e78e","1869.vdb_846d75405b_","1871.v50ffb_786515e","1906.v21c5c13d25c6","1910.v4ca_b_2c639cb_0","1911.vc09e01781005","1917.v9ee8a_39b_3d0d","1925.v62fb_7ffb_08ce","1934.v23cf60a_47fc3","1936.vfa_a_5c2cef4e7","1967.vdea_d580c1a_b_a_","2.0.0","2.0.0-beta-1","2.0.0-beta-2","2.0.1","2.0.1-beta-1","2.0.1-beta-2","2.0.1-beta-3","2.0.1-beta-4","2.0.1-beta-5","2.0.1-beta-6","2.0.2","2.0.3","2.0.4","2.0.4-beta-1","2.0.5","2.0.6","2.0.7","2.0.8","2.10.0","2.10.1","2.10.2","2.10.3","2.10.4","2.11.1","2.11.2","2.11.3","2.11.4","2.11.5","2.2.0","2.2.0-alpha-1","2.2.0-alpha-2","2.2.0-alpha-3","2.2.0-alpha-4","2.2.0-beta-1","2.2.0-beta-2","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.4.0","2.4.0-beta-1","2.4.1","2.4.2","2.4.3-beta-1","2.4.5","2.4.6-beta-1","2.4.6-beta-2","2.5.0","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.5.6","2.5.7","2.5.8","2.6.0","2.7.0","2.7.0-beta1","2.7.1","2.7.2","2.8.0","2.8.2","2.8.3","2.9.0","2.9.1","2.9.2","2.9.3","2.9.4","2.9.5","2.9.6","2.9.7","2.9.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-wg26-8wmj-cf9p/GHSA-wg26-8wmj-cf9p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}