AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-70430

LOW · CVSS 2.7 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Jenkins versions 2.575 and earlier, as well as LTS 2.568.1 and earlier, are vulnerable due to insufficient restrictions on object instantiation within project naming strategy configurations. This flaw enables attackers with Overall/Manage permissions to create arbitrary configuration types, potentially compromising the integrity of the Jenkins environment. Organizations using these affected versions should prioritize patching to mitigate risks associated with unauthorized configuration changes.

CVE
CVE-2026-70430
Severity
LOW
CVSS
2.7
EPSS
0.18%
Jenkins

Original NVD Description

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.