What is CVE-2026-70427?
CVE-2026-70427 allows attackers with control over Jenkins agent processes to leverage unsafe symbolic link handling with empty names during `.tar`/`.tar.gz` extraction, leading to arbitrary file writes on the Jenkins controller. This affects Jenkins 2.575 and earlier, as well as LTS 2.568.1 and earlier. Users should update to the latest Jenkins version.
Azərbaycanca: CVE-2026-70427 Jenkins-də `.tar` və `.tar.gz` arxivlərinin çıxarılması zamanı təhlükəsiz işlənməyən simvolik keçid (symbolic link) boşluğundan istifadə edərək agent proseslərini idarə edə bilən hücumçuların Jenkins kontrollerinə ixtiyari fayl yazmasına imkan verir. Bu zəiflik Jenkins 2.575 və daha əvvəlki versiyalar, həmçinin LTS 2.568.1 və əvvəlki versiyalarına təsir edir. İstifadəçilərə Jenkins-i ən son versiyaya yeniləmələri tövsiyə olunur.
FAQ2
What file operation in Jenkins triggers the CVE-2026-70427 vulnerability?
CVE-2026-70427 is triggered during the extraction of `.tar` and `.tar.gz` archives in Jenkins due to unsafe symbolic link handling with empty names.
What action can an attacker who successfully exploits CVE-2026-70427 perform on the Jenkins controller?
The attacker can write arbitrary files to the Jenkins controller.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.