Deserialization Flaw in Jenkins Core Products
CVE-2026-70426
9CRITICAL
What is CVE-2026-70426?
In certain versions of Jenkins, specifically 2.575 and earlier, including LTS 2.568.1 and prior, a significant deserialization vulnerability exists. The JEP-200 class filter fails to apply to classes resolved through a fallback mechanism in the Remoting deserialization process. This loophole grants agent processes and unauthorized attackers with Agent/Connect permissions the ability to bypass crucial security measures, potentially compromising the integrity of the Jenkins core classpath.
Affected Version(s)
Jenkins 2.576
Remoting 3385.vf1123fb_515da_
Jenkins 2.576