Symlink Vulnerability in Jenkins Project Affecting File Access Permissions
CVE-2026-19429
6.5MEDIUM
What is CVE-2026-19429?
An insufficient patch in Jenkins allows an authenticated remote attacker with Item/Configure permission to exploit the system via crafted tar archives. This flaw permits unauthorized reading of arbitrary files on the Jenkins controller filesystem, including sensitive data such as secrets and configuration files. The security update intended to validate symlink destinations but failed to restrict symlink targets effectively, compromising the integrity of the Jenkins environment.