Missing Permission Checks in Jenkins Sauce OnDemand Plugin by Jenkins
CVE-2026-70445
Currently unrated
What is CVE-2026-70445?
The Jenkins Sauce OnDemand Plugin, version 2.2.0 and earlier, exposes a security vulnerability due to missing permission checks. This flaw allows users with Overall/Read permission to enumerate the credentials IDs stored within Jenkins, potentially leading to unauthorized access to sensitive information. To ensure the security of your Jenkins environment, it's crucial to review the permissions associated with this plugin and apply any available patches or updates as recommended by Jenkins security advisories.
Affected Version(s)
Jenkins Sauce OnDemand Plugin 0 <= 2.2.0