Jenkins · Jenkins Loadninja Plugin · CVE-2026-33003
**Name of the Vulnerable Software and Affected Versions**
Jenkins LoadNinja Plugin versions 2.1 and earlier
**Description**
The Jenkins LoadNinja Plugin stores LoadNinja API keys unencrypted in `config.xml` files on the Jenkins controller. This allows users with Item/Extended Read permission, or access to the Jenkins controller file system, to view the API keys. The vulnerable files are located on the Jenkins controller.
**Recommendations**
Update to a newer version of the Jenkins LoadNinja Plugin that addresses this issue.