Path Traversal Vulnerability in Jenkins by CloudBees
CVE-2026-70428

4.3MEDIUM

Key Information:

Vendor

Jenkins

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-70428?

Jenkins versions 2.575 and earlier, including LTS 2.568.1 and earlier, suffer from a path traversal vulnerability. This occurs when the application fails to properly authenticate file paths in file parameter names. As a result, an attacker with Item/Configure and Item/Build permissions can exploit this weakness to write files to arbitrary locations within the controller file system. This can lead to unauthorized data access or manipulation, posing a significant risk to system integrity.

Affected Version(s)

Jenkins 2.576

Jenkins 2.576

Jenkins 2.568.2 < 2.568.*

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.