CVE-2026-70433: Medium severity Jenkins Jenkins HCL AppScan Plugin vulnerability
Published Aug 5, 2026
·Updated
Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Affected Software
1 affected component
Jenkins Jenkins HCL AppScan Plugin<=1.8.3
Event History
Aug 5, 2026
CVE Published
via MITRE·05:40 PM
Data Sourced
via MITRE·05:40 PM
Description
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-70433?
CVE-2026-70433 has a risk score of 33, indicating a medium level of severity.
2
How do I fix CVE-2026-70433?
To fix CVE-2026-70433, upgrade to Jenkins HCL AppScan Plugin version 1.8.4 or later.
3
What are the implications of CVE-2026-70433?
CVE-2026-70433 allows attackers with Overall/Read permission to enumerate stored credentials IDs, potentially compromising sensitive information.
4
Who is affected by CVE-2026-70433?
Users of Jenkins HCL AppScan Plugin version 1.8.3 and earlier are affected by CVE-2026-70433.
5
Is there a workaround for CVE-2026-70433?
There are no known workarounds for CVE-2026-70433; the best solution is to update the plugin.