CyberRota Analysis
AI-GeneratedJenkins is vulnerable due to improper validation of symlink targets in the FilePath.untarFrom() method, allowing an attacker with Item/Configure permission to create symlinks that point to arbitrary paths on the controller filesystem. This can lead to the exfiltration of sensitive cryptographic material and credentials stored in Jenkins, making it critical for Jenkins administrators and security teams to prioritize patching and mitigating this vulnerability to protect their systems and data.
CVE
CVE-2026-19429
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Original NVD Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.