Medium severity4.3NVD Advisory· Published Aug 5, 2026· Updated Sep 8, 2026
CVE-2026-70428
CVE-2026-70428
Description
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=2.575, <=2.568.1
- osv-coords2 versions
< 2.568.2-r0+ 1 more
- (no CPE)range: < 2.568.2-r0
- (no CPE)range: < 2.568.2
Patches
Vulnerability mechanics
References
1- www.jenkins.io/security/advisory/2026-08-05/nvdVendor Advisory
News mentions
1- Jenkins Security Advisory 2026-08-05Jenkins Security Advisories · Aug 5, 2026