Description
A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Published: 2026-08-05
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing permission check in the Jenkins Parameterized Remote Trigger Plugin allows any user with Overall/Read permission to enumerate the IDs of credentials stored in Jenkins. Although the attacker cannot retrieve the actual secrets directly, having a list of credential IDs can facilitate further attacks such as targeted credential stuffing or reconnaissance, which may threaten confidentiality and potentially integrity of the system.

Affected Systems

Jenkins Project’s Parameterized Remote Trigger Plugin versions 3.2.2 and earlier are affected. Any Jenkins installation that has this plugin installed is vulnerable to credential ID enumeration; the vulnerability could be exploited if the plugin is misused or exposed, which is inferred.

Risk and Exploitability

The vulnerability can be exploited by any account with Overall/Read privileges, which many environments grant to a wide user base. Attackers can call the plugin’s exposed endpoints to list credential IDs. The EPSS score of <1% indicates a very low probability of exploitation, and the issue is not listed in CISA’s KEV catalog, but the lack of an authorization check exposes the system to moderate risk if an attacker gains read access. The CVSS score of 4.3 categorizes it as moderate severity.

Generated by OpenCVE AI on August 6, 2026 at 20:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Parameterized Remote Trigger Plugin to a version newer than 3.2.2 where the permission check has been added.
  • Limit Overall/Read permissions to trusted users or adopt a more granular permission model to restrict access to credential enumeration.
  • If the plugin is not required, remove it from the Jenkins installation to eliminate the attack surface.

Generated by OpenCVE AI on August 6, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Parameterized Remote Trigger Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Parameterized Remote Trigger Plugin

Thu, 06 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Credential Enumeration via Missing Permission in Jenkins Parameterized Remote Trigger Plugin

Thu, 06 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Allows Credential ID Enumeration in Jenkins Parameterized Remote Trigger Plugin
Weaknesses CWE-284

Thu, 06 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Allows Credential ID Enumeration in Jenkins Parameterized Remote Trigger Plugin
Weaknesses CWE-284

Wed, 05 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
References

Subscriptions

Jenkins Project Jenkins Parameterized Remote Trigger Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-08-06T14:54:04.676Z

Reserved: 2026-08-04T14:13:20.602Z

Link: CVE-2026-70438

cve-icon Vulnrichment

Updated: 2026-08-06T14:53:52.113Z

cve-icon NVD

Status : Received

Published: 2026-08-05T18:17:13.583

Modified: 2026-08-06T16:16:53.217

Link: CVE-2026-70438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:32Z

Weaknesses