Unrated severityNVD Advisory· Published Aug 5, 2026
CVE-2026-70430
CVE-2026-70430
Description
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 2.575 and earlier, LTS 2.568.1 and earlier
Patches
Vulnerability mechanics
References
1- www.jenkins.io/security/advisory/2026-08-05/mitrevendor-advisory
News mentions
1- Jenkins Security Advisory 2026-08-05Jenkins Security Advisories · Aug 5, 2026