CVE-2026-70446: Jenkins CodeSonar Plugin vulnerability
Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVE-2026-70446 is a vulnerability in the Jenkins CodeSonar Plugin that allows users with Overall/Read permission to enumerate credential IDs due to missing permission checks.
The severity of CVE-2026-70446 is rated as 26, indicating a significant security risk.
To fix CVE-2026-70446, upgrade to Jenkins CodeSonar Plugin version 3.6.1 or later where the permission checks have been implemented.
Jenkins CodeSonar Plugin versions 3.6.0 and earlier are affected by CVE-2026-70446.
Yes, CVE-2026-70446 can lead to data exposure by allowing unauthorized users to enumerate credential IDs stored in Jenkins.