SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84674

MEDIUM · CVSS 5.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Jenkins XebiaLabs XL Deploy Plugin versions 26.1.0 and earlier are vulnerable due to missing permission checks, enabling attackers with Overall/Read permissions to enumerate stored credential IDs. This exposure could lead to unauthorized access to sensitive information, potentially compromising the integrity of the Jenkins environment. Organizations using this plugin should prioritize patching to mitigate the risk of credential enumeration and subsequent exploitation.

CVE
CVE-2026-84674
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%
Jenkins

Original NVD Description

Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.