AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70428

MEDIUM · CVSS 4.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Jenkins versions 2.575 and earlier, as well as LTS 2.568.1 and earlier, are vulnerable to improper path traversal in file parameter names, enabling users with Item/Configure and Item/Build permissions to write files to arbitrary locations on the controller's file system. This flaw could lead to unauthorized file manipulation, potentially compromising the integrity of the Jenkins environment. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-70428
Severity
MEDIUM
CVSS
4.3
EPSS
0.24%
Jenkins

Original NVD Description

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.