AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70444

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A missing permission check in the Jenkins Violation Comments to GitLab Plugin (versions 2.62.0 and earlier) allows users with Overall/Read permissions to enumerate credential IDs stored in Jenkins. This vulnerability could lead to unauthorized access to sensitive credential information, potentially compromising the security of integrated systems. Organizations using affected versions of Jenkins and the GitLab plugin should prioritize patching to mitigate the risk of credential exposure.

CVE
CVE-2026-70444
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%
Jenkins GitLab

Original NVD Description

A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.