CVE-2026-19429: Jenkins - FilePath.untarFrom() Symlink Target Validation Bypass and Blank-Name Check Bypass (Arbitrary File Read)
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Assume arbitrary file read remains exploitable even in versions patched for CVE-2026-33001 and CVE-2026-70427; restrict/limit users with Item/Configure permission so attackers cannot create workspace symlinks to arbitrary files on the Jenkins controller.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19429?
The severity of CVE-2026-19429 is classified as medium with a score of 6.5.
How do I fix CVE-2026-19429?
To fix CVE-2026-19429, update Jenkins to a version that includes the complete patch for this vulnerability.
What type of access is required to exploit CVE-2026-19429?
An authenticated remote attacker with Item/Configure permission is required to exploit CVE-2026-19429.
What can an attacker do with CVE-2026-19429?
An attacker can read arbitrary files on the Jenkins controller filesystem using a crafted tar archive.
Which versions of Jenkins are affected by CVE-2026-19429?
CVE-2026-19429 affects Jenkins through LTS version 2.555.3.