AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70433

MEDIUM · CVSS 4.3 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The HCL AppScan Plugin for Jenkins versions 1.8.3 and earlier lacks proper permission checks, enabling users with Overall/Read permissions to enumerate stored credential IDs. This vulnerability could lead to unauthorized access to sensitive credentials, posing a significant risk to Jenkins instances. Organizations using this plugin should prioritize remediation to protect their credential management and overall security posture.

CVE
CVE-2026-70433
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%
Jenkins

Original NVD Description

Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.