CVE-2026-70429
HIGHJenkins < 2.576 and LTS < 2.568.2 - Permission Bypass via Case-Insensitive User and Group Name Collision
Title source: llmDescription
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
Jenkins Security Advisory 2026-08-05
https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3924
Scores
CVSS v3
8.1
EPSS
0.0024
EPSS Percentile
15.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-178
Status
published
Products (2)
Jenkins Project/Jenkins
2.568.2 - 2.568.*
Jenkins Project/Jenkins
2.576
Published
Aug 05, 2026
Tracked Since
Aug 05, 2026