CVE-2026-70429: High severity Jenkins Jenkins vulnerability
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70429?
CVE-2026-70429 has a risk score of 51, indicating a medium-level vulnerability.
How do I fix CVE-2026-70429?
To fix CVE-2026-70429, upgrade Jenkins to version 2.576 or later, or LTS 2.568.2 or later.
What vulnerabilities does CVE-2026-70429 introduce?
CVE-2026-70429 allows attackers to impersonate users or gain their permissions by exploiting inconsistent case sensitivity in user and group names.
Which versions of Jenkins are affected by CVE-2026-70429?
Jenkins versions 2.575 and earlier, and LTS versions 2.568.1 and earlier are affected by CVE-2026-70429.
What is the potential impact of CVE-2026-70429 on Jenkins security?
The impact of CVE-2026-70429 can lead to unauthorized access to user accounts and permissions, compromising the security of Jenkins deployments.