All CVEs
Vulnerability intelligence

CVE-2026-70427

Jenkins Project Jenkins

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.

CVSS Score
4.3
Medium
EPSS — Exploit Probability
0.3%
Riskier than 26% of all CVEs · checked 2026-09-18
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Aug 6, 2026 · latest Aug 6, 2026

Coverage timeline

Related CVEs — Jenkins Project