Jenkins CodeSonar Plugin Vulnerability Exposes Credential IDs
CVE-2026-70446
Currently unrated
What is CVE-2026-70446?
The Jenkins CodeSonar Plugin suffers from a vulnerability due to missing permission checks that could allow attackers who possess Overall/Read permission to enumerate credential IDs stored within Jenkins. This flaw highlights a significant oversight in access controls, which can expose sensitive information to unauthorized users, potentially compromising the security of Jenkins environments.
Affected Version(s)
Jenkins CodeSonar Plugin 0 <= 3.6.0