Impact
The vulnerability is a missing permission check in the Jenkins XebiaLabs XL Deploy Plugin. Versions 26.1.0 and earlier allow any user with Overall or Read permission to query the plugin’s endpoint and retrieve identifiers of credentials stored in Jenkins. The primary impact is that an attacker can discover credential IDs, which may enable further attacks such as credential harvesting, lateral movement, or privilege escalation if additional information is later obtained. The weakness is classified as CWE‑862, Authorization Bypass Through User‑Controlled Key.
Affected Systems
This issue affects the Jenkins XebiaLabs XL Deploy Plugin. All installations using version 26.1.0 or any earlier release are impacted; other Jenkins components are not directly affected by this permission gap.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity risk. Although no EPSS score is provided, the lack of an exploit probability metric does not diminish the risk for organizations where users possess Overall/Read privileges. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an authenticated user who already has Overall or Read rights, or an attacker who has gained such privileges through credential compromise or social engineering. In both cases, enumeration of credential IDs can be performed without requiring network‑level access, making the threat accessible to internal or compromised accounts.
OpenCVE Enrichment