Insufficient Permission Checks in Jenkins XebiaLabs XL Deploy Plugin
CVE-2026-84674
5.4MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 2 September 2026
What is CVE-2026-84674?
The Jenkins XebiaLabs XL Deploy Plugin versions 26.1.0 and earlier exhibit a significant security flaw due to missing permission checks. This vulnerability allows attackers with Overall/Read permissions to enumerate stored credential IDs within Jenkins, potentially compromising sensitive information. It highlights the necessity for robust permission validation to safeguard against unauthorized access and information disclosure.
Affected Version(s)
Jenkins XebiaLabs XL Deploy Plugin 0 <= 26.1.0