Intel

AIKIDO-2026-440350

appscan is vulnerable to Missing Authorization

Missing AuthorizationCVE-2026-70433 Published 3 days ago

43

Medium Risk

This Affects:

JAVAappscan
0.0.1 - 1.8.3
Fixed in 1.8.4
Are you affected? Scan for Free

TL;DR

Several HTTP endpoints skip permission checks. An attacker with Overall/Read permission can list credentials IDs stored in Jenkins, which can help capture those credentials when combined with another issue. The fix requires appropriate permissions on the affected endpoints.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and users with Overall/Read permission can reach the plugin HTTP endpoints.

Background info

appscan is vulnerable to Missing Authorization in versions 0.0.1 - 1.8.3.

How to fix this

Upgrade the com.hcl.security:appscan library to the patch version.