CVE-2026-70426
Received Received - Intake

JEP-200 Bypass in Jenkins Remoting

Vulnerability report for CVE-2026-70426, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Jenkins Project

Description

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
jenkins jenkins to 2.575 (exc)
jenkins jenkins to 2.568.1 (exc)
remoting remoting to 3384 (exc)
remoting remoting to 3355.3357 (exc)
jenkins jenkins to 2.576 (exc)
jenkins jenkins to 2.568.2 (exc)
jenkins remoting to 3355.3357.v931d3c992987 (exc)
jenkins remoting From 3384.v60d89463d9e0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Jenkins Remoting versions 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987. It allows bypassing the JEP-200 class filter during deserialization via a fallback path. This means agent processes or attackers with Agent/Connect permission can deserialize classes on the Jenkins core classpath without proper filtering.

Detection Guidance

To detect this vulnerability, check the version of the Remoting library in use. If it is 3384.v60d89463d9e0 or earlier (except 3355.3357.v931d3c992987), the system is vulnerable. Verify Jenkins core version; if it is 2.575 or earlier (LTS 2.568.1 or earlier), the system is affected.

Impact Analysis

If exploited, this vulnerability could allow unauthorized code execution on Jenkins agents or core systems. Attackers with Agent/Connect permission could bypass security controls, potentially leading to data breaches, system compromise, or unauthorized access to sensitive resources.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating compliance requirements under GDPR, HIPAA, or other regulations. Organizations may face legal penalties, reputational damage, or loss of certification if exploited.

Mitigation Strategies

Upgrade Remoting to version 3355.3357.v931d3c992987 or later and Jenkins to version 2.576 or later to apply the JEP-200 class filter correctly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-70426. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart