AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70443

MEDIUM · CVSS 4.3 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Horreum Plugin for Jenkins prior to version 0.16.162.v33b_4a_a_b_5f828 is vulnerable due to improper context settings for credential lookups, enabling attackers with Item/Configure permissions to exfiltrate unauthorized credentials to a specified Horreum URL. This could lead to sensitive information exposure, impacting the integrity and confidentiality of the Jenkins environment. Organizations using this plugin should prioritize applying the latest updates to mitigate potential credential leakage risks.

CVE
CVE-2026-70443
Severity
MEDIUM
CVSS
4.3
EPSS
0.16%
Jenkins

Original NVD Description

Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL.