CVE-2026-70430
Received Received - Intake

Jenkins Configuration Object Instantiation Flaw

Vulnerability report for CVE-2026-70430, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Jenkins Project

Description

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
jenkins jenkins to 2.576 (exc)
jenkins jenkins_lts to 2.569 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Jenkins versions 2.575 and earlier, including LTS 2.568.1 and earlier, allow attackers with Overall/Manage permissions to exploit a flaw in the project naming strategy configuration. This flaw lets them instantiate arbitrary object types, including those restricted to administrators, potentially leading to unauthorized configuration changes.

Detection Guidance

This vulnerability requires Overall/Manage permissions to exploit, so detection involves checking for unauthorized changes to project naming strategies or suspicious object instantiations. Review Jenkins logs for unusual configuration modifications and verify that only authorized users have Overall/Manage permissions.

Impact Analysis

If you are a Jenkins administrator or user with Overall/Manage permissions, an attacker could exploit this to gain unauthorized access to administrative functions. This may allow them to alter configurations, disrupt services, or escalate privileges within your Jenkins environment.

Compliance Impact

This vulnerability could lead to unauthorized access or changes to sensitive data or configurations, potentially violating compliance requirements such as GDPR or HIPAA. Unauthorized modifications may result in data breaches or non-compliance with security policies.

Mitigation Strategies

Upgrade Jenkins to version 2.576 or LTS 2.568.2 or later to address the vulnerability. Restrict Overall/Manage permissions to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-70430. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart