nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-70430 CVE-2026-70430
LOW
Jenkins Project Naming Strategy Unsafe Instantiation
Record summary
CVE-2026-70430 has a selected CVSS score of 2.7 (low).
Description
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | 2.576 to < * | unaffected |
| 2.568.2 to < 2.568.* | unaffected |
References
2Jenkins Security Advisory 2026-08-05Vendor advisory
https://www.jenkins.io/security/advisory/2026-08-05