CVE-2026-70446: Medium severity Jenkins CodeSonar Plugin vulnerability
Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2026-70446?
CVE-2026-70446 is a vulnerability in the Jenkins CodeSonar Plugin that allows users with Overall/Read permission to enumerate credential IDs due to missing permission checks.
What is the severity of CVE-2026-70446?
The severity of CVE-2026-70446 is rated as 26, indicating a significant security risk.
How do I fix CVE-2026-70446?
To fix CVE-2026-70446, upgrade to Jenkins CodeSonar Plugin version 3.6.1 or later where the permission checks have been implemented.
Which versions of Jenkins are affected by CVE-2026-70446?
Jenkins CodeSonar Plugin versions 3.6.0 and earlier are affected by CVE-2026-70446.
Can CVE-2026-70446 lead to data exposure?
Yes, CVE-2026-70446 can lead to data exposure by allowing unauthorized users to enumerate credential IDs stored in Jenkins.