Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-70430

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 7.6%
CVSS Severity
CVSS v3 Score 2.7
Products affected by CVE-2026-70430


Contact Us

Shodan ® - All rights reserved