AUGUST 22, 2026
Live Feed
Back to database
Case File

CVE-2026-19429

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

Jenkins is vulnerable due to improper validation of symlink targets in the FilePath.untarFrom() method, allowing an attacker with Item/Configure permission to create symlinks that point to arbitrary paths on the controller filesystem. This can lead to the exfiltration of sensitive cryptographic material and credentials stored in Jenkins, making it critical for Jenkins administrators and security teams to prioritize patching and mitigating this vulnerability to protect their systems and data.

CVE
CVE-2026-19429
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A

Original NVD Description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.