CVE-2026-48926
BaseFortify
Publication date: 2026-05-27
Last updated on: 2026-05-27
Assigner: Jenkins Project
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| jenkinsci | job_import_plugin | to 143.v044a_2e819b_27 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The Jenkins Job Import Plugin version 143.v044a_2e819b_27 and earlier contains a vulnerability where it does not perform a permission check on a specific HTTP endpoint.
This flaw allows attackers who have Overall/Read permission in Jenkins to enumerate the IDs of credentials stored within Jenkins, potentially exposing sensitive information.
How can this vulnerability impact me? :
This vulnerability can impact you by allowing an attacker with Overall/Read permission to discover credential IDs stored in Jenkins.
While the attacker may not have full access to the credentials themselves, enumerating credential IDs can aid in further attacks or reconnaissance, potentially compromising the security of your Jenkins environment.