CyberRota Analysis
AI-GeneratedThe HCL AppScan Plugin for Jenkins versions 1.8.3 and earlier lacks proper permission checks, enabling users with Overall/Read permissions to enumerate stored credential IDs. This vulnerability could lead to unauthorized access to sensitive credentials, posing a significant risk to Jenkins instances. Organizations using this plugin should prioritize remediation to protect their credential management and overall security posture.
CVE
CVE-2026-70433
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%
Jenkins
Original NVD Description
Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.