CVE-2026-33004Disclosure(jenkins / loadninja)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • loadninja

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-18); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
loadninja

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-18: 1Mentions · 2026-03-21: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-21: 103-1803-21
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 『For archives extracted on the controller, this can result in code execution』 CVE-2026-33001、CVE-2026-33002、CVE-2026-33003、CVE-2026-33004 Jenkins Security Advisory 2026-03-18 https://www.jenkins.io/security/advisory/2026-03-18/

    Post summary

    The advisory announces that extracting archives on Jenkins controllers via CVE‑2026‑33001‑04 can lead to code execution, but no PoC, exploit, or patch details are provided in the excerpt.

    00020450
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33004 Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, increasing the potential for attackers to observe a… https://www.cve.org/CVERecord?id=CVE-2026-33004

    Post summary

    CVE-2026-33004 highlights that the Jenkins LoadNinja plugin fails to mask API keys on job configuration forms, exposing them to potential attackers.

    00000113
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjenkinsloadninja-jenkins-

Explore more