CVE-2026-19429

Published Aug 10, 2026

Last updated 6 days ago

Jenkins

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-19429 is a vulnerability found in Linux Foundation Jenkins, affecting versions up to 2.555.3. This issue resides within the Tar Extraction component, specifically in the `FilePath.java` file, and is categorized as a symlink vulnerability (CWE-61). The vulnerability stems from an incomplete patch for a prior security flaw (CVE-2026-33001). It allows an authenticated remote attacker, possessing `Item/Configure` permission, to read arbitrary files on the Jenkins controller filesystem by submitting a specially crafted tar archive. This could lead to the disclosure of sensitive configuration files, such as `secrets/master.key` and `credentials.xml`. The attack can be launched remotely, and while technical details are available, no public exploit currently exists.

Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Source
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
NVD status
Rejected

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.