CVE-2026-70428: Jenkins

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.

Affected products

  • Jenkins Jenkins: before 2.568.2 (fixed in 2.568.2); before 2.576 (fixed in 2.576)

Published 2026-08-05. Last modified 2026-09-08.