Description
Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Published: 2026-08-05
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing permission checks in Jenkins AWS CodeBuild Plugin version 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs stored in Jenkins. This disclosure enables an adversary to gather identifiers of stored credentials without direct access to the credential values, potentially facilitating further credential‑based attacks if additional privileges are obtained.

Affected Systems

Affected systems include Jenkins Project's Jenkins AWS CodeBuild Plugin version 0.59 and earlier. Users of Jenkins deployments that have installed this plugin are potentially exposed.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and no EPSS score is available. The vulnerability is not listed in CISA KEV, indicating no current evidence of exploitation. However, the ability to enumerate credential IDs with read access poses a moderate risk, as an attacker who already has overall or read permissions could use the enumeration information to target specific credentials or amplify an existing compromise. The attack vector is inferred to be local or network based within the Jenkins environment, requiring only read rights, which many users possess.

Generated by OpenCVE AI on August 5, 2026 at 21:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Jenkins AWS CodeBuild Plugin to the latest version that corrects the missing permission checks (for example, 0.60 or later).
  • Restrict the Overall/Read permission to only trusted users or service accounts that truly require it; consider tightening network controls around Jenkins nodes.
  • Monitor Jenkins audit logs for suspicious credential‑ID enumeration activity and review credential usage patterns for potential abuse.

Generated by OpenCVE AI on August 5, 2026 at 21:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Aws Codebuild Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Aws Codebuild Plugin

Wed, 05 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Credential Enumeration via Missing Permission Checks in Jenkins AWS CodeBuild Plugin
Weaknesses CWE-284
CWE-285

Wed, 05 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
References

Subscriptions

Jenkins Project Jenkins Aws Codebuild Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-08-05T19:31:22.329Z

Reserved: 2026-08-04T14:13:20.603Z

Link: CVE-2026-70447

cve-icon Vulnrichment

Updated: 2026-08-05T19:30:52.799Z

cve-icon NVD

Status : Received

Published: 2026-08-05T18:17:14.570

Modified: 2026-08-05T20:17:16.277

Link: CVE-2026-70447

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:17Z

Weaknesses