What is CVE-2026-70426?
This critical vulnerability in Jenkins Remoting allows authenticated agent processes to achieve remote code execution (RCE) due to the deserialization fallback path bypassing the JEP-200 class filter. Affected versions include Jenkins 2.575 and LTS 2.568.1 and earlier. Immediate update to the latest patched versions is strongly recommended.
Azərbaycanca: Bu kritik boşluq Jenkins-in Remoting komponentində JEP-200 klass filtrinin düzgün tətbiq edilməməsi səbəbindən autentifikasiya olunmuş agent proseslərinə uzaqdan kod icrası (RCE) imkanı yaradır. Jenkins 2.575 və LTS 2.568.1 daxil olmaqla əvvəlki versiyalar təsirlənir. Təhlükəsizlik yaması tətbiq edilən ən son versiyalara təcili yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
In which Jenkins component was CVE-2026-70426 discovered and what is its root cause?
The vulnerability was discovered in the Jenkins Remoting component due to improper implementation of the JEP-200 class filter.
Which Jenkins versions are affected by this critical vulnerability?
Jenkins 2.575 and LTS 2.568.1, including all earlier versions, are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.