nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-70427 CVE-2026-70427
MEDIUM
Jenkins Archive Extraction Symlink Arbitrary File Write
Record summary
CVE-2026-70427 has a selected CVSS score of 4.3 (medium).
Description
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | 2.576 to < * | unaffected |
| 2.568.2 to < 2.568.* | unaffected |
References
2Jenkins Security Advisory 2026-08-05Vendor advisory
https://www.jenkins.io/security/advisory/2026-08-05