Path Traversal Vulnerability in Jenkins by CloudBees
CVE-2026-70428
4.3MEDIUM
What is CVE-2026-70428?
Jenkins versions 2.575 and earlier, including LTS 2.568.1 and earlier, suffer from a path traversal vulnerability. This occurs when the application fails to properly authenticate file paths in file parameter names. As a result, an attacker with Item/Configure and Item/Build permissions can exploit this weakness to write files to arbitrary locations within the controller file system. This can lead to unauthorized data access or manipulation, posing a significant risk to system integrity.
Affected Version(s)
Jenkins 2.576
Jenkins 2.576
Jenkins 2.568.2 < 2.568.*