CVE-2026-70444: Medium severity Jenkins Violation Comments to GitLab Plugin vulnerability
A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70444?
CVE-2026-70444 has a risk rating of 33, indicating it poses a moderate threat to security.
What does CVE-2026-70444 exploit in Jenkins Violation Comments to GitLab Plugin?
CVE-2026-70444 exploits a missing permission check that allows unauthorized users to enumerate stored credential IDs.
How do I fix CVE-2026-70444?
To fix CVE-2026-70444, upgrade to Jenkins Violation Comments to GitLab Plugin version 2.62.1 or later.
Who is affected by CVE-2026-70444?
Any Jenkins instance using Violation Comments to GitLab Plugin version 2.62.0 or earlier with Overall/Read permission granted can be affected.
What impact does CVE-2026-70444 have on Jenkins users?
CVE-2026-70444 can lead to credential information exposure, risking unauthorized access to sensitive data.