CVE-2026-70445: Medium severity Jenkins Sauce OnDemand Plugin vulnerability
Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70445?
CVE-2026-70445 has a risk rating of 26, indicating a high level of vulnerability.
How do I fix CVE-2026-70445?
To fix CVE-2026-70445, upgrade to the Jenkins Sauce OnDemand Plugin version 2.2.1 or later which addresses the missing permission checks.
What are the consequences of CVE-2026-70445?
The consequence of CVE-2026-70445 is that attackers with Overall/Read permission can enumerate sensitive credential IDs stored in Jenkins.
Which versions of Jenkins Sauce OnDemand Plugin are affected by CVE-2026-70445?
CVE-2026-70445 affects versions 2.2.0 and earlier of the Jenkins Sauce OnDemand Plugin.
Is my Jenkins instance vulnerable to CVE-2026-70445?
If you are running Jenkins Sauce OnDemand Plugin version 2.2.0 or earlier, then your instance is vulnerable to CVE-2026-70445.