CVE-2026-42522
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Apr 29, 2026
Vendor
unknown
Description
A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.