Description
Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL.
Published: 2026-08-05
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Jenkins Horreum Plugin version 0.16.162.v33b_4a_a_b_5f828 and earlier fails to set the correct context for credential lookup, allowing an attacker with Item/Configure permission to cause Jenkins to send credentials they are not entitled to use to an administrator‑configured Horreum URL. This flaw results in the unintended disclosure of secrets, which is a form of improper access control and information exposure (CWE‑269). The CVSS score of 4.3 indicates a medium severity vulnerability that threatens the confidentiality of stored credentials.

Affected Systems

The affected product is the Jenkins Horreum Plugin distributed by the Jenkins Project. Versions 0.16.162.v33b_4a_a_b_5f828 and earlier are impacted. Administrators should verify the exact version in use and plan to upgrade to a fixed release.

Risk and Exploitability

The CVSS score of 4.3 combined with the lack of EPSS data suggests that the flaw can be exploited by any user who has been granted Item/Configure rights. Those rights commonly allow changes to build configuration, so an insider or a compromised user could trigger the credential leak to a malicious external endpoint. The vulnerability is not listed in the CISA KEV catalog, which indicates no known widespread exploitation at this time, but the risk to confidentiality remains significant, especially in environments where credential reuse or external integrations are common.

Generated by OpenCVE AI on August 5, 2026 at 23:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Jenkins Horreum Plugin to the latest available version to receive the fix.
  • Restrict Item/Configure permissions to trusted users only, revoking them from accounts that do not require build configuration modifications.
  • Configure the Horreum URL endpoint with authentication and enforce outbound network restrictions to prevent accidental credential leakage.

Generated by OpenCVE AI on August 5, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Horreum Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Horreum Plugin

Wed, 05 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Credential Leakage via Horreum Plugin Context Misconfiguration

Wed, 05 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Improper Credential Context in Jenkins Horreum Plugin Allows Unauthorized Credential Leakage
Weaknesses CWE-200
CWE-284

Wed, 05 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Improper Credential Context in Jenkins Horreum Plugin Allows Unauthorized Credential Leakage
Weaknesses CWE-200
CWE-269
CWE-284
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL.
References

Subscriptions

Jenkins Project Jenkins Horreum Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-08-05T19:37:23.588Z

Reserved: 2026-08-04T14:13:20.603Z

Link: CVE-2026-70443

cve-icon Vulnrichment

Updated: 2026-08-05T19:37:18.075Z

cve-icon NVD

Status : Received

Published: 2026-08-05T18:17:14.137

Modified: 2026-08-05T20:17:15.707

Link: CVE-2026-70443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:25Z

Weaknesses
  • CWE-269

    Improper Privilege Management