Jenkins has disclosed a critical security vulnerability that could allow attackers to execute malicious code on a Jenkins controller by bypassing a security filter used in agent-to-controller communications. Tracked as CVE-2026-70426, the flaw affects Jenkins installations using vulnerable versions of the Remoting library. The issue has received a Critical CVSS severity rating. It impacts Jenkins 2.575 and earlier, as well as Jenkins LTS 2.568.1 and earlier. The vulnerability exists in Remoting versions 3384.v60d89463d9e0 and earlier, except for version 3355.3357.v931d3c992987. Jenkins uses its Remoting library, commonly distributed as agent.jar or remoting.jar, to enable communication between the central controller and connected...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!