Permission Check Flaw in Jenkins HCL AppScan Plugin Exposes Sensitive Credentials
CVE-2026-70433
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-70433?
An issue exists in the Jenkins HCL AppScan Plugin versions up to 1.8.3 where inadequate permission checks allow users with Overall/Read permissions to access and enumerate the IDs of credentials stored within Jenkins. This exposes sensitive information that could lead to unauthorized access and potential compromise of the Jenkins instance.
Affected Version(s)
Jenkins HCL AppScan Plugin 0 <= 1.8.3