What is CVE-2026-70428?
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier contain a path traversal vulnerability in file parameter names, allowing attackers with Item/Configure and Item/Build permissions to write files to arbitrary locations on the controller file system. Updating to the latest Jenkins release is strongly recommended.
Azərbaycanca: Jenkins-in 2.575 və LTS 2.568.1 və daha əvvəlki versiyalarında fayl parametr adlarında path traversal zəifliyi aşkarlanıb. Bu, Item/Configure və Item/Build icazələrinə malik hücumçulara Jenkins kontroller fayl sistemində ixtiyari yerlərə fayl yazmağa imkan verir. Dərhal Jenkins-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What permissions does an attacker need to exploit CVE-2026-70428?
The attacker needs Item/Configure and Item/Build permissions.
Which Jenkins versions are affected by the CVE-2026-70428 path traversal vulnerability?
Jenkins 2.575 and earlier, as well as LTS 2.568.1 and earlier, are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.