CVE-2026-70430: Low severity Jenkins Jenkins vulnerability
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
For Jenkins versions that allow instantiation via the project naming strategy configuration (Jenkins 2.575 and earlier, LTS 2.568.1 and earlier), restrict the ability to use Overall/Manage permissions (limit it to trusted administrators only) so attackers cannot create/instantiate arbitrary configuration-related object types.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70430?
CVE-2026-70430 has a risk score of 44, indicating a significant security vulnerability in Jenkins.
How do I fix CVE-2026-70430?
To fix CVE-2026-70430, upgrade Jenkins to version 2.576 or later or LTS 2.568.2 or later.
What types of attacks can be executed due to CVE-2026-70430?
CVE-2026-70430 allows attackers with Overall/Manage permission to instantiate arbitrary types, which may lead to configuration manipulation.
Which versions of Jenkins are affected by CVE-2026-70430?
Versions of Jenkins including 2.575 and earlier, and LTS 2.568.1 and earlier are affected by CVE-2026-70430.
Who is vulnerable to CVE-2026-70430?
Users of Jenkins with Overall/Manage permissions are vulnerable to CVE-2026-70430.