CVE-2026-70427 Details
Description
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.
A vulnerability exists in Jenkins versions through 2.575 and LTS through 2.568.1, where the extraction of .tar and .tar.gz archives does not properly manage symbolic links with nearly empty names. This flaw enables attackers who can control agent processes to send manipulated archives to the Jenkins controller, potentially writing files to any location on the file system. The only limitation is the file system access rights of the user running Jenkins. This vulnerability could be exploited to execute code by, for example, placing harmful scripts in the JENKINS_HOME/init.groovy.d/ directory or installing malicious plugins in the JENKINS_HOME/plugins/ directory.
Users are advised to update Jenkins to version 2.576 or LTS 2.568.2. If an immediate update is not possible, a workaround is available. Details can be found in the Jenkins Security Advisory 2026-08-05.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3930 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| jenkins jenkins | < 2.568.2 < 2.576 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | Initial Analysis | [email protected] |
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |