AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-70426

CRITICAL · CVSS 9 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Jenkins versions 2.575 and earlier, as well as LTS 2.568.1 and earlier, are vulnerable due to a flaw in the Remoting deserialization implementation, where the JEP-200 class filter is not enforced for classes resolved through fallback paths. This vulnerability allows agents and attackers with Agent/Connect permissions to bypass security measures, potentially leading to unauthorized code execution. Organizations using affected Jenkins versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-70426
Severity
CRITICAL
CVSS
9
EPSS
0.29%
Jenkins

Original NVD Description

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath.