Improper access control in Jenkins and Jenkins LTS - CVE-2026-70430
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected application does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration. A remote administrator can instantiate any types related to configuration .
Affected software
Jenkins LTS
How to mitigate CVE-2026-70430
Jenkins LTS - update to 2.568.2