CVE-2026-19429
Published Aug 10, 2026
Last updated 6 days ago
AI description
CVE-2026-19429 is a vulnerability found in Linux Foundation Jenkins, affecting versions up to 2.555.3. This issue resides within the Tar Extraction component, specifically in the `FilePath.java` file, and is categorized as a symlink vulnerability (CWE-61). The vulnerability stems from an incomplete patch for a prior security flaw (CVE-2026-33001). It allows an authenticated remote attacker, possessing `Item/Configure` permission, to read arbitrary files on the Jenkins controller filesystem by submitting a specially crafted tar archive. This could lead to the disclosure of sensitive configuration files, such as `secrets/master.key` and `credentials.xml`. The attack can be launched remotely, and while technical details are available, no public exploit currently exists.
- Description
- Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- Source
- 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
- NVD status
- Rejected
- Hype score
- Not currently trending
🚨*CVE* CVE-2026-19429 Jenkins FilePath.untarFrom() (all versions) validates symlink destinations but not targets, bypassing CVE-2026-33001. Any user with Item/Build access can trigger extr… https://t.co/GWaDKJY3rr ----- Traducción: CVE-2026-19429 Jen… https://t.co/utmtNg
@infoflowcloud
10 Aug 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-19429 Jenkins FilePath.untarFrom() (all versions) validates symlink destinations but not targets, bypassing CVE-2026-33001. Any user with Item/Build access can trigger extr… https://t.co/fy6FwVfDf2
@CVEnew
10 Aug 2026
1511 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes