AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70446

MEDIUM · CVSS 4.3 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Jenkins CodeSonar Plugin versions 3.6.0 and earlier are vulnerable due to missing permission checks, enabling users with Overall/Read permissions to enumerate stored credential IDs. This exposure could lead to unauthorized access to sensitive credentials, potentially compromising the security of Jenkins environments. Organizations using affected versions of the plugin should prioritize remediation to mitigate the risk of credential enumeration and subsequent attacks.

CVE
CVE-2026-70446
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%
Jenkins

Original NVD Description

Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.