Junglewise Threat Intelligence

CVE-2026-48926: Jenkins Job Import Plugin missing permission check in HTTP endpoint

CVE-2026-48926 · Severity: medium · CVSS 4.3 · Published 2026-05-27

Technologies: org.jenkins-ci.plugins:job-import-plugin (Maven). Vendors: Jenkins Project, Jenkins, Maven.

Executive brief

The Jenkins Job Import Plugin, which allows users to import jobs from other Jenkins instances, contains a security flaw where it fails to verify user permissions on a specific web endpoint. This allows an authenticated user with basic read access to discover the unique identifiers (IDs) of credentials stored within the Jenkins system. While this does not directly reveal passwords, these IDs can be used in combination with other vulnerabilities to potentially steal sensitive credentials, compromising the security of the entire automation platform.

Technical details

A missing permission check (CWE-269) exists in an HTTP endpoint within the Jenkins Job Import Plugin versions 143.v044a_2e819b_27 and earlier. An attacker with 'Overall/Read' permissions can exploit this flaw to enumerate the IDs of credentials stored in the Jenkins controller. While this is an information disclosure vulnerability, these IDs are often required as prerequisites for more complex attacks aimed at credential theft. This issue stems from an incomplete fix for a previous security issue (SECURITY-2791). The vulnerability is addressed in version 143.145.v48f9a, which implements proper 'Job Import/Import Jobs' permission requirements.

Affected products

  • Jenkins Project Job Import Plugin <= 143.v044a_2e819b_27

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory
  • 2026-05-27: patched

References

Related threats