9
CVE-2026-70426
- EPSS 0.29%
- Veröffentlicht 05.08.2026 17:40:27
- Zuletzt bearbeitet 06.08.2026 05:17:05
- CVE-Watchlists
- Unerledigt
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerJenkins Project
≫
Produkt
Jenkins
Default Statusaffected
Version
2.576
Version <
*
Status
unaffected
Version
2.568.2
Version <
2.568.*
Status
unaffected
HerstellerJenkins Project
≫
Produkt
Remoting
Default Statusaffected
Version
3385.vf1123fb_515da_
Version <
*
Status
unaffected
Version
3355.3357.v931d3c992987
Version <
3355.*
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.215 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 9 | 2.2 | 6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3911