CVE-2026-70445: Jenkins Sauce OnDemand Plugin vulnerability
Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVE-2026-70445 has a risk rating of 26, indicating a high level of vulnerability.
To fix CVE-2026-70445, upgrade to the Jenkins Sauce OnDemand Plugin version 2.2.1 or later which addresses the missing permission checks.
The consequence of CVE-2026-70445 is that attackers with Overall/Read permission can enumerate sensitive credential IDs stored in Jenkins.
CVE-2026-70445 affects versions 2.2.0 and earlier of the Jenkins Sauce OnDemand Plugin.
If you are running Jenkins Sauce OnDemand Plugin version 2.2.0 or earlier, then your instance is vulnerable to CVE-2026-70445.