jenkins: Jenkins: Arbitrary file write via path traversal
Published Aug 5, 2026
8.8
HIGHCVSS 3.1
EPSS 0.43%
Description
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.
Affected products
No data.
No data.
OpenShift Developer Tools and Services 4.12
ocp-tools-4/jenkins-rhel8:1786628667
Fixed · RHSA-2026:60247
OpenShift Developer Tools and Services 4.13
ocp-tools-4/jenkins-rhel8:1786628681
Fixed · RHSA-2026:60249
OpenShift Developer Tools and Services 4.14
ocp-tools-4/jenkins-rhel8:1786533561
Fixed · RHSA-2026:60248
OpenShift Developer Tools and Services 4.15
ocp-tools-4/jenkins-rhel8:1786533565
Fixed · RHSA-2026:60239
OpenShift Developer Tools and Services 4.16
ocp-tools-4/jenkins-rhel9:1787125166
Fixed · RHSA-2026:60251
OpenShift Developer Tools and Services 4.17
ocp-tools-4/jenkins-rhel9:1787124635
Fixed · RHSA-2026:60246
OpenShift Developer Tools and Services 4.18
ocp-tools-4/jenkins-rhel9:1787125069
Fixed · RHSA-2026:60250
OpenShift Developer Tools and Services 4.19
ocp-tools-4/jenkins-rhel9:1787124632
Fixed · RHSA-2026:60252
OpenShift Developer Tools and Services 4.20
ocp-tools-4/jenkins-rhel9:1787124925
Fixed · RHSA-2026:60259
OpenShift Developer Tools and Services 4.21
ocp-tools-4/jenkins-rhel9:1787125311
Fixed · RHSA-2026:60254
OpenShift Developer Tools and Services 4.22
ocp-tools-4/jenkins-rhel9:1787124779
Fixed · RHSA-2026:60256
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Developer Tools and Services 4.12 | ocp-tools-4/jenkins-rhel8:1786628667 | Fixed | RHSA-2026:60247 |
| OpenShift Developer Tools and Services 4.13 | ocp-tools-4/jenkins-rhel8:1786628681 | Fixed | RHSA-2026:60249 |
| OpenShift Developer Tools and Services 4.14 | ocp-tools-4/jenkins-rhel8:1786533561 | Fixed | RHSA-2026:60248 |
| OpenShift Developer Tools and Services 4.15 | ocp-tools-4/jenkins-rhel8:1786533565 | Fixed | RHSA-2026:60239 |
| OpenShift Developer Tools and Services 4.16 | ocp-tools-4/jenkins-rhel9:1787125166 | Fixed | RHSA-2026:60251 |
| OpenShift Developer Tools and Services 4.17 | ocp-tools-4/jenkins-rhel9:1787124635 | Fixed | RHSA-2026:60246 |
| OpenShift Developer Tools and Services 4.18 | ocp-tools-4/jenkins-rhel9:1787125069 | Fixed | RHSA-2026:60250 |
| OpenShift Developer Tools and Services 4.19 | ocp-tools-4/jenkins-rhel9:1787124632 | Fixed | RHSA-2026:60252 |
| OpenShift Developer Tools and Services 4.20 | ocp-tools-4/jenkins-rhel9:1787124925 | Fixed | RHSA-2026:60259 |
| OpenShift Developer Tools and Services 4.21 | ocp-tools-4/jenkins-rhel9:1787125311 | Fixed | RHSA-2026:60254 |
| OpenShift Developer Tools and Services 4.22 | ocp-tools-4/jenkins-rhel9:1787124779 | Fixed | RHSA-2026:60256 |
No package ranges for this CVE.
Remediation
Red Hat statement
Important: This flaw in Jenkins allows authenticated attackers with Item/Configure and Item/Build permissions to perform path traversal via file parameter names, leading to arbitrary file writes on the controller file system. This could result in arbitrary code execution and compromise of the Jenkins instance, but requires existing elevated privileges within the application, limiting the attack surface to trusted users.
Red Hat mitigation
To mitigate this issue, restrict the `Item/Configure` and `Item/Build` permissions within Jenkins to only highly trusted users. This limits the pool of potential attackers who could exploit the path traversal vulnerability. Additionally, implement robust monitoring of the Jenkins controller's file system for any unauthorized write operations, which could indicate an attempted exploitation.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-70428 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2511664 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53571 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-70428
- https://www.cve.org/CVERecord?id=CVE-2026-70428
- https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3927 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-70428 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2511664 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53571 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-70428 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-70428 | ||
| https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3927 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data