Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 05 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Jenkins Remoting Deserialization Bypass Allows Arbitrary Code Execution via Agent |
Wed, 05 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-502 | |
| Metrics |
cvssV3_1
|
Wed, 05 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-08-05T18:16:23.441Z
Reserved: 2026-08-04T14:13:20.602Z
Link: CVE-2026-70426
Updated: 2026-08-05T18:16:13.114Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T19:30:05Z