CVE-2026-70430

LOW

Jenkins < 2.576 and LTS < 2.568.2 - Authenticated Arbitrary Object Instantiation via Project Naming Strategy

Title source: llm
STIX 2.1

Description

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
Jenkins Security Advisory 2026-08-05
https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3916

Scores

CVSS v3 2.7
EPSS 0.0018
EPSS Percentile 7.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
Jenkins Project/Jenkins 2.568.2 - 2.568.*
Jenkins Project/Jenkins 2.576
Published Aug 05, 2026
Tracked Since Aug 05, 2026