AI description
CVE-2026-70426 is a vulnerability identified in Jenkins that allows for a bypass of the JEP-200 deserialization filter. This flaw exists in Remoting versions 3384.v60d89463d9e0 and earlier, with the exception of version 3355.3357.v931d3c992987, and affects Jenkins 2.575 and earlier, as well as LTS 2.568.1 and earlier. The vulnerability stems from the Remoting deserialization implementation, where the JEP-200 class filter is not consistently applied to classes resolved through a fallback path. This oversight enables attackers with Agent/Connect permission, or those who can execute code on an agent, to bypass the intended deserialization protections and execute code on the Jenkins controller.
- Description
- In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath.
- Source
- jenkinsci-cert@googlegroups.com
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 9
- Impact score
- 6
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-502
- Hype score
- Not currently trending
Top #CVE to #patch this week 👀 - @VMware #ESXi 9.0 RCE (CVE-2026-47876, CVE-2026-41703) - @JetBrains #TeamCity RCE (CVE-2026-63077, CVE-2026-65907) - #Jenkins Core (CVE-2026-70426) - @zohocorp ManageEngine ADAudit RCE (CVE-2026-6516) - @IBM Langflow RCE (CVE-2026-9198) -
@stansecure
13 Aug 2026
51 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-70426: Jenkinsの重大なリモートコード実行の脆弱性により、逆シリアル化フィルタが回避される CVE-2026-70426: Critical Jenkins RCE Flaw Bypasses Deserialization Filter #DailyCyberSecurity (Aug 6) https://t.co/06JiwVFT0q
@foxbook
6 Aug 2026
296 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-70426: A critical Jenkins vulnerability allows attackers to bypass the JEP-200 filter and achieve remote code execution (RCE) on the controller. Organizations using affected Jenkins instances should apply security updates immediately. #Jenkins #CVE #RCE #DevSecOps
@ThreatWire_
6 Aug 2026
2870 Impressions
14 Retweets
36 Likes
11 Bookmarks
0 Replies
0 Quotes
🚨CVE-2026-70426 🚨 Proud to announce CVE-2026-70426 (SECURITY-3911), a Critical (CVSS 9.8) JEP-200 class filter bypass in Jenkins Remoting leading to RCE on the Controller 🔗 Official Advisory: https://t.co/ZOGW9vHGaM #BugBounty https://t.co/gCkFCMFx7Q
@txp__9
5 Aug 2026
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes