Critical severity9.0NVD Advisory· Published Aug 5, 2026· Updated Aug 31, 2026
CVE-2026-70426
CVE-2026-70426
Description
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: <=3384.v60d89463d9e0, except 3355.3357.v931d3c992987
- Range: <=2.575, LTS <=2.568.1
- osv-coords2 versions
< 2.568.2+ 1 more
- (no CPE)range: < 2.568.2
- (no CPE)range: < 2.568.2-r0
Patches
Vulnerability mechanics
References
1News mentions
4- ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and MoreThe Hacker News · Aug 31, 2026
- Weekly Cyber Security Newsletter — OWASP Top 10 for LLM, Cisco IOS XE Flaw, and 1-Click Cursor RCE +20 StoriesCyber Security News · Aug 9, 2026
- Critical Jenkins Vulnerability Allows Attackers to Execute Malicious Code on ControllerCyber Security News · Aug 6, 2026
- Jenkins Security Advisory 2026-08-05Jenkins Security Advisories · Aug 5, 2026