Description
Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Published: 2026-08-05
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing permission check in Jenkins HCL AppScan Plugin versions 1.8.3 and earlier allows an attacker who has Overall/Read access to enumerate the IDs of credentials stored in Jenkins. The vulnerability description indicates that the plugin exposes credential identifiers to users lacking proper permission protection. Based on the description, it is inferred that obtaining these credential IDs could aid an attacker in further credential theft or compromise operations within the Jenkins environment.

Affected Systems

The affected product is the Jenkins HCL AppScan Plugin for Jenkins, specifically versions 1.8.3 and any earlier release. Users running these versions are at risk of exposing credential identifiers to unauthorized individuals.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, indicating no publicly documented exploits as of the data provided. The CVSS score of 4.3 indicates moderate severity. The likely attack vector is any user who can log in with Overall/Read privileges. Because the plugin performs the enumeration without additional checks, the risk is elevated in environments where read permissions are broadly granted. Organizations should treat this as a moderate-impact information-disclosure vulnerability and prioritize remediation.

Generated by OpenCVE AI on August 6, 2026 at 18:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Jenkins HCL AppScan Plugin to the latest version that implements proper permission checks.
  • Restrict the Overall/Read permission to trusted accounts or use group-based controls to limit exposure.
  • Audit Jenkins user roles and remove unnecessary read access to reduce the attack surface.

Generated by OpenCVE AI on August 6, 2026 at 18:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Hcl Appscan Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Hcl Appscan Plugin

Thu, 06 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Credential ID Enumeration via Missing Permission Check in Jenkins HCL AppScan Plugin

Thu, 06 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Credentials Enumeration via Missing Permission Checks in Jenkins HCL AppScan Plugin
Weaknesses CWE-284

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Credentials Enumeration via Missing Permission Checks in Jenkins HCL AppScan Plugin
Weaknesses CWE-284

Wed, 05 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
References

Subscriptions

Jenkins Project Jenkins Hcl Appscan Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-08-06T15:01:30.026Z

Reserved: 2026-08-04T14:13:20.602Z

Link: CVE-2026-70433

cve-icon Vulnrichment

Updated: 2026-08-06T15:00:41.652Z

cve-icon NVD

Status : Received

Published: 2026-08-05T18:17:13.030

Modified: 2026-08-06T16:16:52.423

Link: CVE-2026-70433

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:41Z

Weaknesses