Symbolic Link Handling Issue in Jenkins by CloudBees
CVE-2026-70427
4.3MEDIUM
What is CVE-2026-70427?
A vulnerability in Jenkins allows attackers to exploit improper handling of symbolic links when extracting .tar and .tar.gz archives. By crafting malicious archive files, an attacker capable of controlling agent processes can trick the Jenkins controller into writing files to unauthorized locations on the file system. The impact is restricted only by the file system access permissions of the user running Jenkins, which can lead to significant security risks. Proper sanitization and handling of symbolic links are crucial to mitigate this issue.
Affected Version(s)
Jenkins 2.576
Jenkins 2.576
Jenkins 2.568.2 < 2.568.*