Data Exposure Vulnerability in Jenkins LoadNinja Plugin by CloudBees
CVE-2026-33003
4.3MEDIUM
What is CVE-2026-33003?
The Jenkins LoadNinja Plugin versions 2.1 and earlier improperly handle LoadNinja API keys by storing them in an unencrypted format within job config.xml files on the Jenkins controller. This configuration exposes sensitive information to users who possess Item or Extended Read permissions, as well as to individuals with access to the Jenkins controller file system. This vulnerability presents a significant risk, allowing unauthorized users to potentially access the API keys stored in the configuration files.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins LoadNinja Plugin 0 <= 2.1