CVE-2026-70430
Jenkins vulnerability analysis and mitigation

Overview

CVE-2026-70430 is a low-severity improper access control vulnerability in Jenkins core, tracked as SECURITY-3916, that allows attackers with Overall/Manage permission to instantiate arbitrary object types as part of the project naming strategy configuration — including types intended exclusively for administrator-level configuration. It affects Jenkins weekly releases up to and including 2.575 and LTS releases up to and including 2.568.1. The vulnerability was disclosed on August 5, 2026, as part of the Jenkins Security Advisory 2026-08-05. It carries a CVSS v3.1 base score of 2.7 (Low) (Jenkins Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-284 (Improper Access Control): Jenkins fails to restrict the types of objects that can be instantiated when processing the project naming strategy configuration, allowing a broader set of configuration-related types than intended to be instantiated by non-administrator users. An attacker with the Overall/Manage permission — a privileged but non-administrator role — can supply crafted configuration input that causes Jenkins to instantiate arbitrary configuration-related Java types, including those reserved for administrator use. Exploitation requires network access to the Jenkins instance and a valid account with Overall/Manage permission; no user interaction is required. The vulnerability was reported by Vitaly Simonovich through the Jenkins Bug Bounty Program sponsored by the European Commission (Jenkins Advisory).

Impact

Successful exploitation allows an attacker with Overall/Manage permission to make unauthorized configuration changes by instantiating arbitrary configuration-related object types, potentially altering Jenkins system behavior in ways normally restricted to administrators. The CVSS assessment indicates no confidentiality or availability impact, with only a low integrity impact, as the attacker cannot read sensitive data or disrupt service but may be able to manipulate configuration state. The scope is limited to the Jenkins controller itself, and there is no direct path to code execution or lateral movement from this vulnerability alone (Jenkins Advisory, GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been observed as of the advisory publication date. The CISA SSVC assessment confirms exploitation status as "none" and the attack is not automatable. The EPSS score is approximately 0.17–0.18%, placing it in the 8th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Jenkins Advisory, GitHub Advisory).

Mitigation and workarounds

Jenkins has released fixed versions that restrict object instantiation in the project naming strategy configuration to only types related to that feature. Users should upgrade Jenkins weekly to version 2.576 or later, or Jenkins LTS to version 2.568.2 or later. As an interim workaround, organizations should restrict the Overall/Manage permission to trusted administrators only, minimizing the attack surface until patching is feasible (Jenkins Advisory).

Community reactions

The vulnerability was disclosed as part of a broader Jenkins Security Advisory on August 5, 2026, which included multiple higher-severity issues (including a Critical-rated deserialization filter bypass, CVE-2026-70426). Security aggregators such as AusCERT, Tenable, and VulDB indexed the advisory shortly after publication. Given the low CVSS score and absence of public exploits, community attention has been minimal compared to the more severe vulnerabilities disclosed in the same advisory (Jenkins Advisory).

Additional resources


SourceThis report was generated using AI

Related Jenkins vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-70429HIGH8.1
  • Jenkins logoJenkins
  • jenkins-2.568
NoYesAug 05, 2026
CVE-2026-70428MEDIUM4.3
  • Jenkins logoJenkins
  • jenkins
NoYesAug 05, 2026
CVE-2026-70427MEDIUM4.3
  • Jenkins logoJenkins
  • jenkins-2.568
NoYesAug 05, 2026
CVE-2026-70430LOW2.7
  • Jenkins logoJenkins
  • jenkins
NoYesAug 05, 2026
CVE-2026-19429NONEN/A
  • Jenkins logoJenkins
  • cpe:2.3:a:jenkins:jenkins
NoNoAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management