CVE-2026-70428: Path Traversal
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jenkinsto a version that resolves this vulnerability.Fixed in 2.575 - Upgrade
Upgrade
Jenkins LTSto a version that resolves this vulnerability.Fixed in 2.568.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70428?
The severity of CVE-2026-70428 is rated as 55.
How do I fix CVE-2026-70428?
To fix CVE-2026-70428, upgrade your Jenkins installation to version 2.576 or later.
What is the impact of CVE-2026-70428?
CVE-2026-70428 allows attackers with specific permissions to write files to arbitrary locations on the Jenkins controller file system.
Which versions of Jenkins are affected by CVE-2026-70428?
Jenkins versions 2.575 and earlier, as well as Jenkins LTS versions 2.568.1 and earlier, are affected by CVE-2026-70428.
What type of vulnerability is CVE-2026-70428 classified as?
CVE-2026-70428 is classified as a path traversal vulnerability.