Vulnerability intelligence
CVE-2026-70427
Jenkins Project Jenkins
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.
CVSS Score
4.3
Medium
EPSS — Exploit Probability
0.3%
Riskier than 26% of all CVEs · checked 2026-09-18
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Aug 6, 2026 · latest Aug 6, 2026
Coverage timeline
-
Critical Jenkins flaw lets attackers bypass filter for RCEsecurityonline.info · Aug 6, 2026