CVE-2026-70430: Jenkins Jenkins vulnerability
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
For Jenkins versions that allow instantiation via the project naming strategy configuration (Jenkins 2.575 and earlier, LTS 2.568.1 and earlier), restrict the ability to use Overall/Manage permissions (limit it to trusted administrators only) so attackers cannot create/instantiate arbitrary configuration-related object types.