<Vulnerability name="CVE-2026-70428">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-05T17:40:28</PublicDate>
    <Bugzilla id="2511664" url="https://bugzilla.redhat.com/show_bug.cgi?id=2511664" xml:lang="en:us">
jenkins: Jenkins: Arbitrary file write via path traversal
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>8.8</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-22</CWE>
    <Details xml:lang="en:us" source="Mitre">
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Jenkins. Attackers with specific permissions (Item/Configure and Item/Build) can exploit this vulnerability. By manipulating file parameter names, they can bypass security checks and write files to any location on the Jenkins controller's file system. This path traversal vulnerability could lead to unauthorized code execution or disrupt the system's availability.
    </Details>
    <PackageState cpe="cpe:/a:redhat:ocp_tools">
        <ProductName>OpenShift Developer Tools and Services</ProductName>
        <FixState>Affected</FixState>
        <PackageName>jenkins</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-70428
https://nvd.nist.gov/vuln/detail/CVE-2026-70428
https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3927
    </References>
</Vulnerability>