PatchSiren cyber security CVE debrief
CVE-2026-48926 Jenkins Project CVE debrief
A missing permission check in Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs stored in Jenkins. This information disclosure vulnerability (CWE-269) has a CVSS 3.1 score of 4.3 (Medium severity). The issue was disclosed in the Jenkins security advisory dated 2026-05-27. No known exploitation in the wild or ransomware campaign use has been reported.
- Vendor
- Jenkins Project
- Product
- Jenkins Job Import Plugin
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-05-27
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-05-27
Who should care
Jenkins administrators, DevOps engineers, and security teams managing CI/CD infrastructure with Job Import Plugin deployments
Technical summary
The Jenkins Job Import Plugin fails to perform permission checks on an HTTP endpoint, enabling attackers with only Overall/Read permission to enumerate credentials IDs. This exposes sensitive credential identifiers without requiring higher privileges, facilitating potential credential-based attacks. The vulnerability affects versions 143.v044a_2e819b_27 and earlier.
Defensive priority
medium
Recommended defensive actions
- Review Jenkins Job Import Plugin installations and upgrade to a version newer than 143.v044a_2e819b_27
- Audit Jenkins credential store access logs for unauthorized enumeration attempts
- Verify that Jenkins users with Overall/Read permission have legitimate business need for that access level
- Apply principle of least privilege by restricting Overall/Read permission to necessary personnel only
- Monitor for plugin updates addressing SECURITY-3783 in Jenkins update center
Evidence notes
Vulnerability confirmed via official Jenkins security advisory (SECURITY-3783). CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N. CWE-269 (Improper Privilege Management) identified.
Official resources
-
CVE-2026-48926 CVE record
CVE.org
-
CVE-2026-48926 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
2026-05-27