AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70438

MEDIUM · CVSS 4.3 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Parameterized Remote Trigger Plugin in Jenkins versions 3.2.2 and earlier is vulnerable due to a missing permission check, enabling attackers with Overall/Read permissions to enumerate stored credential IDs. This exposure could lead to unauthorized access to sensitive credentials, increasing the risk of further exploitation within the Jenkins environment. Organizations using affected versions of Jenkins should prioritize this vulnerability to safeguard their credential management and overall security posture.

CVE
CVE-2026-70438
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%
Jenkins

Original NVD Description

A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.