Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-70427

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 16.1%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2026-70427


Contact Us

Shodan ® - All rights reserved