Back

HIGH

jenkins: Jenkins: Arbitrary file write via path traversal

Published Aug 5, 2026

Description

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.

Affected products

Remediation

Red Hat statement

Important: This flaw in Jenkins allows authenticated attackers with Item/Configure and Item/Build permissions to perform path traversal via file parameter names, leading to arbitrary file writes on the controller file system. This could result in arbitrary code execution and compromise of the Jenkins instance, but requires existing elevated privileges within the application, limiting the attack surface to trusted users.

Red Hat mitigation

To mitigate this issue, restrict the `Item/Configure` and `Item/Build` permissions within Jenkins to only highly trusted users. This limits the pool of potential attackers who could exploit the path traversal vulnerability. Additionally, implement robust monitoring of the Jenkins controller's file system for any unauthorized write operations, which could indicate an attempted exploitation.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner jenkins
Published Aug 5, 2026
Updated Aug 5, 2026
Reserved Aug 4, 2026

CISA Vulnrichment

Updated Aug 5, 2026

NVD

Status Analyzed
Modified Sep 8, 2026

Red Hat

Severity Important
Public date Aug 5, 2026
Bugzilla 2511664

ENISA EUVD

Assigner jenkins
Published Aug 5, 2026
Updated Aug 5, 2026

GitHub

No data