Improper access control in Jenkins and Jenkins LTS - CVE-2026-70430

 

Improper access control in Jenkins and Jenkins LTS - CVE-2026-70430

Published: August 6, 2026


Vulnerability identifier: #VU141079
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-70430
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the affected application does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration. A remote administrator can instantiate any types related to configuration .


Affected software

Jenkins
Jenkins LTS

How to mitigate CVE-2026-70430

Install updates from vendor's website.

Jenkins - update to 2.576
Jenkins LTS - update to 2.568.2

External References

Related Security Bulletins