CVE-2026-33001 Details
Description
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.
A vulnerability exists in Jenkins versions through 2.554 and LTS through 2.541.2, where symbolic links are not properly managed during the extraction of .tar and .tar.gz files. This flaw allows crafted archives to write files to arbitrary locations on the filesystem, limited only by the file system access permissions of the user running Jenkins. Exploitation could lead to the execution of malicious scripts or the installation of harmful plugins on the Jenkins controller. The vulnerability can be exploited by attackers with Item/Configure permission or those who can control agent processes.
Users should update Jenkins to version 2.555 or LTS 2.541.3. Additionally, Jenkins administrators should remove permissions from the anonymous user.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:10199 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:10201 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:10204 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:10205 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:10206 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:10209 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:10211 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:10213 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:10214 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:10215 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-33001 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2448645 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33001.json | redhat-SADP | |
| https://www.jenkins.io/security/advisory/2026-03-18/#SECURITY-3657 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | redhat-SADP |
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| jenkins jenkins | < 2.541.3 < 2.555 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | [email protected] |
| Sep 9, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Mar 20, 2026 | Initial Analysis | [email protected] |
| Mar 19, 2026 | CVE Modified | CISA-ADP |
| Mar 18, 2026 | New CVE Received | [email protected] |