CVE-2026-70426 Affecting jenkins-2.568 package, versions <2.568.2-r0


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.45% (38th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-JENKINS2568-18912926
  • published18 Aug 2026
  • disclosed5 Aug 2026

Introduced: 5 Aug 2026

CVE-2026-70426  (opens in a new tab)

How to fix?

Upgrade Chainguard jenkins-2.568 to version 2.568.2-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream jenkins-2.568 package and not the jenkins-2.568 package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath.

CVSS Base Scores

version 3.1