Description
Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Published: 2026-08-05
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Jenkins Sauce OnDemand Plugin versions 2.2.0 and earlier contain missing permission checks that allow anyone with Overall/Read access to enumerate the identifiers of credentials stored in Jenkins. This enumeration exposes credential IDs, which is an information disclosure vulnerability. No additional evidence is provided that enumeration leads to credential theft or other attacks; the impact is limited to disclosure of IDs.

Affected Systems

The affected product is the Jenkins Sauce OnDemand Plugin version 2.2.0 and all earlier releases. Any Jenkins installation that has this plugin installed and users possessing even basic read privileges is vulnerable. The vulnerability does not affect the core Jenkins engine directly but impacts plugins handling credential storage.

Risk and Exploitability

An attacker with Overall/Read permissions can use the plugin’s API or UI to request credential identifiers, bypassing intended permission checks. The EPSS score of <1% signals a very low exploitation probability, and the issue is not listed in KEV, indicating no known public exploitation yet. The CVSS score of 4.3 reflects the potential for information disclosure via credential ID enumeration. The attack path is straightforward for any user that has read access on the Jenkins instance.

Generated by OpenCVE AI on August 6, 2026 at 19:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Sauce OnDemand Plugin to the latest version that includes proper permission checks to prevent credential enumeration.
  • Limit Overall/Read permissions or enforce role‑based access control so that only trusted users can view credentials.
  • If an immediate update cannot be applied, remove the plugin from the Jenkins installation until a fix is available.

Generated by OpenCVE AI on August 6, 2026 at 19:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Sauce Ondemand Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Sauce Ondemand Plugin

Thu, 06 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Credential ID Enumeration in Jenkins Sauce OnDemand Plugin via Missing Permission Checks

Thu, 06 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Jenkins Sauce OnDemand Plugin Allows Credential ID Enumeration
Weaknesses CWE-284

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Jenkins Sauce OnDemand Plugin Allows Credential ID Enumeration
Weaknesses CWE-284

Wed, 05 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
References

Subscriptions

Jenkins Project Jenkins Sauce Ondemand Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-08-06T14:52:13.695Z

Reserved: 2026-08-04T14:13:20.603Z

Link: CVE-2026-70445

cve-icon Vulnrichment

Updated: 2026-08-05T19:43:58.579Z

cve-icon NVD

Status : Received

Published: 2026-08-05T18:17:14.347

Modified: 2026-08-06T16:16:53.370

Link: CVE-2026-70445

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:21Z

Weaknesses