CVE-2026-70426

Published Aug 5, 2026

Last updated 14 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-70426 is a vulnerability identified in Jenkins that allows for a bypass of the JEP-200 deserialization filter. This flaw exists in Remoting versions 3384.v60d89463d9e0 and earlier, with the exception of version 3355.3357.v931d3c992987, and affects Jenkins 2.575 and earlier, as well as LTS 2.568.1 and earlier. The vulnerability stems from the Remoting deserialization implementation, where the JEP-200 class filter is not consistently applied to classes resolved through a fallback path. This oversight enables attackers with Agent/Connect permission, or those who can execute code on an agent, to bypass the intended deserialization protections and execute code on the Jenkins controller.

Description
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath.
Source
jenkinsci-cert@googlegroups.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
9
Impact score
6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-502

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.