CVE-2026-70445

EUVD-2026-53539
Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
jenkinsCNA
UNKNOWN
---
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
jenkinssauce_ondemand
𝑥
≤ 2.2.0
CNA