Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 02 Jun 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins job Import |
|
| CPEs | cpe:2.3:a:jenkins:job_import:*:*:*:*:*:jenkins:*:* cpe:2.3:a:jenkins:job_import:143.v044a_2e819b_27:*:*:*:*:jenkins:*:* |
|
| Vendors & Products |
Jenkins
Jenkins job Import |
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins Project
Jenkins Project jenkins Job Import Plugin |
|
| Vendors & Products |
Jenkins Project
Jenkins Project jenkins Job Import Plugin |
Wed, 27 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Jenkins Job Import Plugin allows enumeration of stored credential IDs due to missing permission check |
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 | |
| Metrics |
cvssV3_1
|
Wed, 27 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-05-27T15:21:36.888Z
Reserved: 2026-05-26T14:50:46.813Z
Link: CVE-2026-48926
Updated: 2026-05-27T15:21:26.719Z
Status : Analyzed
Published: 2026-05-27T15:16:32.310
Modified: 2026-06-17T10:55:24.827
Link: CVE-2026-48926
No data.
OpenCVE Enrichment
Updated: 2026-05-30T21:21:51Z