Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances.
Metrics
Affected Vendors & Products
References
History
Thu, 06 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Case‑Insensitive User and Group Name Handling Allows Impersonation in Jenkins |
Thu, 06 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Inconsistent Case Handling of User and Group Names in Jenkins Allows Impersonation | |
| Weaknesses | CWE-287 |
Thu, 06 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-178 | |
| Metrics |
cvssV3_1
|
Wed, 05 Aug 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Inconsistent Case Handling of User and Group Names in Jenkins Allows Impersonation | |
| First Time appeared |
Jenkins Project
Jenkins Project jenkins |
|
| Weaknesses | CWE-287 | |
| Vendors & Products |
Jenkins Project
Jenkins Project jenkins |
Wed, 05 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-08-06T15:08:29.147Z
Reserved: 2026-08-04T14:13:20.602Z
Link: CVE-2026-70429
Updated: 2026-08-06T15:07:49.971Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-06T19:30:05Z