Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.
History

Thu, 06 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unrestricted Object Instantiation in Jenkins Project Naming Strategy

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unrestricted Object Instantiation in Jenkins Project Naming Strategy
First Time appeared Jenkins Project
Jenkins Project jenkins
Weaknesses CWE-284
Vendors & Products Jenkins Project
Jenkins Project jenkins

Wed, 05 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-08-06T15:05:21.518Z

Reserved: 2026-08-04T14:13:20.602Z

Link: CVE-2026-70430

cve-icon Vulnrichment

Updated: 2026-08-06T15:04:12.654Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T17:30:16Z