
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33004 is a credential masking vulnerability in the Jenkins LoadNinja Plugin that exposes LoadNinja API keys in plaintext on the job configuration form. Affecting LoadNinja Plugin versions 2.1 and earlier, the flaw allows any authenticated user who can view the job configuration page to observe and capture API keys. It was disclosed on March 18, 2026, as part of the Jenkins Security Advisory SECURITY-3642 (which also covers the related storage issue CVE-2026-33003). The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Jenkins Advisory).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The LoadNinja Plugin fails to mask API key fields on the Jenkins job configuration form, rendering them in plaintext HTML rather than as password-type inputs. An authenticated attacker with at minimum read access to a job's configuration page can directly view the API key in the browser UI or by inspecting the page source. No special tooling or exploitation technique is required beyond having a valid Jenkins account with Item/Read permission (Jenkins Advisory).
Successful exploitation allows an authenticated attacker to capture LoadNinja API keys, which could then be used to access the LoadNinja load testing service under the victim organization's account. This could result in unauthorized use of load testing resources, exposure of test configurations and results, or potential abuse of the API to disrupt testing workflows. The confidentiality impact is limited to the API key itself, with no direct integrity or availability impact on the Jenkins instance (Jenkins Advisory).
http://<jenkins-host>/job/<job-name>/configure).view-source: or browser developer tools)./job/<job-name>/configure from unexpected users or IP addresses, particularly outside normal business hours.JENKINS_HOME/jobs/<job-name>/config.xml for the presence of plaintext LoadNinja API keys (related to CVE-2026-33003), which may indicate the broader credential exposure issue (Jenkins Advisory).The Jenkins project has released LoadNinja Plugin version 2.2, which both encrypts stored API keys and masks them on the job configuration form. Administrators should update the LoadNinja Plugin to version 2.2 or later immediately via the Jenkins Plugin Manager. As an interim workaround, restrict Item/Read and Item/Extended Read permissions on jobs configured with the LoadNinja Plugin to only trusted users, and rotate any LoadNinja API keys that may have been exposed (Jenkins Advisory).
The vulnerability was reported by Adam Jordan and disclosed through the Jenkins Security Advisory process on March 18, 2026. Several security news outlets covered the broader Jenkins advisory batch (which included higher-severity CVEs such as CVE-2026-33001 and CVE-2026-33002), with coverage from SecurityOnline, GBHackers, CyberPress, and CyberSecurityNews focusing primarily on the RCE and DNS rebinding issues rather than CVE-2026-33004 specifically (SecurityOnline, GBHackers).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."