Intel

AIKIDO-2026-214219

scm-manager is vulnerable to Missing Authorization

Missing AuthorizationCVE-2026-70435 Published Aug 8, 2026

42

Medium Risk

This Affects:

JAVAscm-manager
0.0.1 - 1.11.1
Fixed in 1.12.1
Are you affected? Scan for Free

TL;DR

Several HTTP endpoints skip permission checks when connecting to attacker-specified HTTP URLs with attacker-specified credentials IDs. An attacker with Overall/Read permission can capture credentials stored in Jenkins. The fix requires Item/Configure permission on those endpoints.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and users with Overall/Read permission can reach the plugin HTTP endpoints.

Background info

scm-manager is vulnerable to Missing Authorization in versions 0.0.1 - 1.11.1.

How to fix this

Upgrade the io.jenkins.plugins:scm-manager library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform