LOWVulnerability

CVE-2026-70430

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.

Properties

severity
LOW
score
2.7
cve_id
CVE-2026-70430
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
published_at
2026-08-05T18:17:12.663
last_modified
2026-08-31T19:34:59.477

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Access Control

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-70430 — Ninja Signal Threat Intelligence | Ninja Signal