Missing Permission Checks in Jenkins Sauce OnDemand Plugin by Jenkins
CVE-2026-70445

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
5 August 2026

What is CVE-2026-70445?

The Jenkins Sauce OnDemand Plugin, version 2.2.0 and earlier, exposes a security vulnerability due to missing permission checks. This flaw allows users with Overall/Read permission to enumerate the credentials IDs stored within Jenkins, potentially leading to unauthorized access to sensitive information. To ensure the security of your Jenkins environment, it's crucial to review the permissions associated with this plugin and apply any available patches or updates as recommended by Jenkins security advisories.

Affected Version(s)

Jenkins Sauce OnDemand Plugin 0 <= 2.2.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.