CVE-2026-70427
Received Received - Intake

Jenkins Archive Extraction Path Traversal Vulnerability

Vulnerability report for CVE-2026-70427, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Jenkins Project

Description

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
jenkins jenkins to 2.576 (exc)
jenkins jenkins to 2.569 (exc)
jenkins jenkins to 2.568.2 (exc)
jenkins remoting to 3384.v60d89463d9e0 (exc)
jenkins remoting From 3355.3357.v931d3c992987 (exc)
jenkins jenkins_lts to 2.569 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Jenkins versions 2.575 and earlier, and LTS 2.568.1 and earlier. It involves unsafe handling of symbolic links with empty names during extraction of tar or tar.gz archives. Attackers who control agent processes can exploit this to write files to arbitrary locations on the file system, limited only by the permissions of the Jenkins user.

Impact Analysis

If exploited, this vulnerability could allow attackers to overwrite critical system files, install malware, or gain unauthorized access to sensitive data. It may lead to complete system compromise depending on the Jenkins user's permissions.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality requirements or HIPAA's security rules. Organizations may face compliance violations, fines, or legal consequences if exploited.

Mitigation Strategies

Upgrade Jenkins to version 2.576 or later for the weekly release, or to LTS 2.568.2 or later for the long-term support release to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-70427. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart