AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70429

HIGH · CVSS 8.1 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Jenkins versions 2.575 and earlier, as well as LTS 2.568.1 and earlier, have a vulnerability in the handling of case-insensitivity for user and group names. This inconsistency allows attackers to create new users or groups that can impersonate existing users, potentially gaining unauthorized access to their permissions. Organizations using these affected versions should prioritize remediation to prevent potential impersonation and privilege escalation attacks.

CVE
CVE-2026-70429
Severity
HIGH
CVSS
8.1
EPSS
0.24%
Jenkins

Original NVD Description

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances.