Medium severity6.5NVD Advisory· Published Aug 5, 2026· Updated Sep 8, 2026
CVE-2026-70429
CVE-2026-70429
Description
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=2.575, LTS <=2.568.1
- osv-coords2 versions
< 2.568.2-r0+ 1 more
- (no CPE)range: < 2.568.2-r0
- (no CPE)range: < 2.568.2
Patches
Vulnerability mechanics
References
1- www.jenkins.io/security/advisory/2026-08-05/nvdVendor Advisory
News mentions
1- Jenkins Security Advisory 2026-08-05Jenkins Security Advisories · Aug 5, 2026