CVE-2026-57293Medium· 4.3▾ SunlitJenkins Gitee Plugin has an incorrect permission check that allows enumerating credentials IDs
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.3%
Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier does not correctly perform a permission check in an HTTP endpoint.
This allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins. Those can be used as part of an attack to capture the credentials using another vulnerability.
An enumeration of credentials IDs in Gitee Plugin 1292.v2559f2f3f2c0 requires Overall/Administer permission.
org.jenkins-ci.plugins:gitee < 1292.v2559f2f3f2c0Upgrade to a patched release:
org.jenkins-ci.plugins:gitee 1292.v2559f2f3f2c0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57291Medium· 5.4Jenkins Gitee Plugin missing permission checks
CVE-2026-57292Medium· 5.4Jenkins Gitee Plugin has a cross-site request forgery vulnerability
CVE-2026-57304Medium· 5.4Jenkins Assembla Plugin has a missing permission check
CVE-2026-57286Medium· 4.3Jenkins Git Parameter Plugin has a missing permission check that allows listing SCM branch and tag names
CVE-2026-57285Medium· 4.3Jenkins GitHub Branch Source Plugin has missing permission check that allows enumerating GitHub Enterprise server URLs
CVE-2026-57301High· 8.8Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE