
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-70430 is a low-severity improper access control vulnerability in Jenkins core, tracked as SECURITY-3916, that allows attackers with Overall/Manage permission to instantiate arbitrary object types as part of the project naming strategy configuration — including types intended exclusively for administrator-level configuration. It affects Jenkins weekly releases up to and including 2.575 and LTS releases up to and including 2.568.1. The vulnerability was disclosed on August 5, 2026, as part of the Jenkins Security Advisory 2026-08-05. It carries a CVSS v3.1 base score of 2.7 (Low) (Jenkins Advisory, GitHub Advisory).
The root cause is classified as CWE-284 (Improper Access Control): Jenkins fails to restrict the types of objects that can be instantiated when processing the project naming strategy configuration, allowing a broader set of configuration-related types than intended to be instantiated by non-administrator users. An attacker with the Overall/Manage permission — a privileged but non-administrator role — can supply crafted configuration input that causes Jenkins to instantiate arbitrary configuration-related Java types, including those reserved for administrator use. Exploitation requires network access to the Jenkins instance and a valid account with Overall/Manage permission; no user interaction is required. The vulnerability was reported by Vitaly Simonovich through the Jenkins Bug Bounty Program sponsored by the European Commission (Jenkins Advisory).
Successful exploitation allows an attacker with Overall/Manage permission to make unauthorized configuration changes by instantiating arbitrary configuration-related object types, potentially altering Jenkins system behavior in ways normally restricted to administrators. The CVSS assessment indicates no confidentiality or availability impact, with only a low integrity impact, as the attacker cannot read sensitive data or disrupt service but may be able to manipulate configuration state. The scope is limited to the Jenkins controller itself, and there is no direct path to code execution or lateral movement from this vulnerability alone (Jenkins Advisory, GitHub Advisory).
There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been observed as of the advisory publication date. The CISA SSVC assessment confirms exploitation status as "none" and the attack is not automatable. The EPSS score is approximately 0.17–0.18%, placing it in the 8th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Jenkins Advisory, GitHub Advisory).
Jenkins has released fixed versions that restrict object instantiation in the project naming strategy configuration to only types related to that feature. Users should upgrade Jenkins weekly to version 2.576 or later, or Jenkins LTS to version 2.568.2 or later. As an interim workaround, organizations should restrict the Overall/Manage permission to trusted administrators only, minimizing the attack surface until patching is feasible (Jenkins Advisory).
The vulnerability was disclosed as part of a broader Jenkins Security Advisory on August 5, 2026, which included multiple higher-severity issues (including a Critical-rated deserialization filter bypass, CVE-2026-70426). Security aggregators such as AusCERT, Tenable, and VulDB indexed the advisory shortly after publication. Given the low CVSS score and absence of public exploits, community attention has been minimal compared to the more severe vulnerabilities disclosed in the same advisory (Jenkins Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."