CVE-2026-70438 Details
Description
A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
A vulnerability exists in the Jenkins Parameterized Remote Trigger Plugin in versions through 3.2.2, due to a missing permission check in HTTP endpoints. This flaw allows attackers with Overall/Read permission to enumerate the IDs of credentials stored in Jenkins. These credential IDs can potentially be exploited to capture the credentials using other vulnerabilities.
Users of the Parameterized Remote Trigger Plugin should update to version 3.2.3 or later, as this version includes the necessary permission checks. If an immediate update is not possible, consider reviewing and restricting Overall/Read permissions to minimize the risk of exploitation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3768 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | CISA-ADP |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |