CVE-2026-48926 PUBLISHED

Assigner: jenkins
Reserved: 26.05.2026 Published: 27.05.2026 Updated: 27.05.2026

Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

Product Status

Vendor Jenkins Project
Product Jenkins Job Import Plugin
Versions Default: unaffected
  • affected from 0 to 143.v044a_2e819b_27 (incl.)

References