Permission Check Flaw in Jenkins HCL AppScan Plugin Exposes Sensitive Credentials
CVE-2026-70433

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
5 August 2026

What is CVE-2026-70433?

An issue exists in the Jenkins HCL AppScan Plugin versions up to 1.8.3 where inadequate permission checks allow users with Overall/Read permissions to access and enumerate the IDs of credentials stored within Jenkins. This exposes sensitive information that could lead to unauthorized access and potential compromise of the Jenkins instance.

Affected Version(s)

Jenkins HCL AppScan Plugin 0 <= 1.8.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.