AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70427

MEDIUM · CVSS 4.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Jenkins versions 2.575 and earlier, as well as LTS 2.568.1 and earlier, are vulnerable due to improper handling of symbolic links with empty names during the extraction of `.tar` and `.tar.gz` archives. This flaw allows attackers with control over agent processes to craft malicious archives, potentially writing files to arbitrary locations on the file system based on the permissions of the Jenkins user. Organizations utilizing affected Jenkins versions should prioritize patching to mitigate the risk of unauthorized file system access.

CVE
CVE-2026-70427
Severity
MEDIUM
CVSS
4.3
EPSS
0.25%
Jenkins

Original NVD Description

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.