PatchSiren cyber security CVE debrief
CVE-2026-70443 Jenkins Project CVE debrief
The CVE-2026-70443 record details a vulnerability in Jenkins Horreum Plugin versions 0.16.162.v33b_4a_a_b_5f828 and earlier. This vulnerability allows attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL, due to improper context setting for credentials lookup. The issue can lead to potential credential misuse. Administrators should prioritize patching the plugin to prevent this vulnerability. Evidence is limited, and defenders should verify affected deployments, review official advisories, and monitor for suspicious credential usage. This CVE was published on 2026-08-05T18:17:14.137Z and has not been modified since then.
- Vendor
- Jenkins Project
- Product
- Jenkins Horreum Plugin
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-05
- Original CVE updated
- 2026-08-05
- Advisory published
- 2026-08-05
- Advisory updated
- 2026-08-05
Who should care
Jenkins administrators, security teams, and users with Item/Configure permissions should be aware of this vulnerability. They should review the official CVE record and assess their deployments for potential exposure. Affected operators and platforms should prioritize patching and review compensating controls for exposed systems. Vulnerability management and security teams should monitor for suspicious credential usage and track exceptions for remediated assets.
Technical summary
Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL. This issue can lead to potential credential misuse. The vulnerability is related to improper handling of credentials in the plugin, and administrators should prioritize patching the plugin to prevent this vulnerability. Affected operators and platforms should review compensating controls for exposed systems while remediation is scheduled and verified.
Defensive priority
Administrators should prioritize patching Jenkins Horreum Plugin to prevent potential credential misuse.
Recommended defensive actions
- Patch Jenkins Horreum Plugin to version beyond 0.16.162.v33b_4a_a_b_5f828
- Restrict Item/Configure permissions to trusted users
- Monitor Jenkins for suspicious credential usage
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record indicates Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup. This allows attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL. Evidence is limited, and defenders should verify affected deployments, review official advisories, and monitor for suspicious credential usage.
Official resources
-
CVE-2026-70443 CVE record
CVE.org
-
CVE-2026-70443 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T18:17:14.137Z and has not been modified since then.