CVE-2026-70438

EUVD-2026-53532
A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
jenkinsCNA
UNKNOWN
---
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
jenkinsparameterized_remote_trigger
𝑥
≤ 3.2.2
CNA