CVE-2026-19429: Jenkins Project Jenkins - Symlink Target Validation Bypass Arbitrary File Read

Published Aug 10, 2026
·
Updated

An incomplete patch for CVE-2026-33001 in Jenkins Project Jenkins through LTS 2.555.3 allows an authenticated remote attacker with Item/Configure permission to read arbitrary files on the Jenkins controller filesystem via a crafted tar archive. The CVE-2026-33001 security update validates symlink destinations during tar extraction in FilePath.java but does not validate symlink targets; a symlink whose location is inside the workspace can still point to arbitrary paths outside it, enabling disclosure of any file readable by the Jenkins process user, including secrets/master.key, credentials.xml, and other sensitive configuration files.

Other sources

Jenkins FilePath.untarFrom() (all versions) validates symlink destinations but not targets, bypassing CVE-2026-33001. Any user with Item/Build access can trigger extraction of a malicious tar via POST /job/{name}/build, planting symlinks to secrets/master.key, secrets/hudson.util.Secret, and credentials.xml. Files are read via GET /job/{name}/lastBuild/consoleText. These three files enable offline AES decryption of all stored Jenkins credentials, escalating to admin access and RCE.

NVD

Affected Software

1 affected component
Jenkins Jenkins<=2.555.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Jenkins Project Jenkins to a version that resolves this vulnerability.

    Fixed in 2.555.3
  2. Compensating control

    Restrict access so only trusted users can have Item/Configure permission (and Item/Build if applicable), because authenticated attackers with Item/Configure can read arbitrary files via crafted tar archives and Item/Build users can trigger malicious tar extraction via POST /job/{name}/build.

Event History

Aug 10, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-19429?

The severity of CVE-2026-19429 is classified as medium with a score of 6.5.

2

How do I fix CVE-2026-19429?

To fix CVE-2026-19429, update Jenkins to a version that includes the complete patch for this vulnerability.

3

What type of access is required to exploit CVE-2026-19429?

An authenticated remote attacker with Item/Configure permission is required to exploit CVE-2026-19429.

4

What can an attacker do with CVE-2026-19429?

An attacker can read arbitrary files on the Jenkins controller filesystem using a crafted tar archive.

5

Which versions of Jenkins are affected by CVE-2026-19429?

CVE-2026-19429 affects Jenkins through LTS version 2.555.3.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203