{"id":"CVE-2026-70428","description":"Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.","cvssScore":4.3,"cvssVersion":"3.1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cvssMetrics":[{"version":"3.1","score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","sourceName":"CISA-ADP","type":"Secondary"}],"cwes":["CWE-22"],"resolved":"MITIGATED-BY-RASP","published":"2026-08-05","lastModified":"2026-09-08","affectedProducts":[{"vendor":"jenkins","product":"jenkins","versionEnd":"\u003c2.568.2"},{"vendor":"jenkins","product":"jenkins","versionEnd":"\u003c2.576"}],"totalAffectedProducts":1,"references":[{"url":"https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3927","source":"jenkinsci-cert@googlegroups.com","tags":["Vendor Advisory"]}],"reasoning":{"decidingSource":"secure-rule-match","decidingReason":"Promoted to MITIGATED-BY-RASP (security rule): this CVE's weakness (CWE-22: Path Traversal) can be mitigated by an ARMR path-traversal security rule that blocks this class of attack at the JVM level, without requiring a CVE-specific patch.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"no-match"},{"rule":"cna-maven-package","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"CNA declares the affected component is a Maven artifact"},{"rule":"patch-hint","stage":"disposition","outcome":"no-match"},{"rule":"open-source-maven","stage":"disposition","outcome":"no-match"},{"rule":"poc-derivable","stage":"disposition","outcome":"no-match"},{"rule":"no-exploit","stage":"disposition","outcome":"matched","status":"NO-FIX-IDENTIFIED","detail":"No public exploits or POCs found in Exploit-DB, Nuclei templates, or GitHub POC repositories, and CISA's Vulnrichment assessment records no demonstrated exploit. No upstream fix reference or open-source Maven package was found either, so there is nothing to act on from either direction."},{"rule":"secure-rule-match","stage":"disposition","outcome":"matched","status":"MITIGATED-BY-RASP","detail":"CWE-22 (Path Traversal) is mitigable by an ARMR path-traversal security rule.","decisive":true},{"rule":"below-action-threshold","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit-published","stage":"disposition","outcome":"skipped"}],"affectedProducts":[{"vendor":"jenkins","product":"jenkins","isKnown":false,"cpe":"cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"full","mechanisms":["security-rule"]},"action":{"state":"available","type":"security-rule"},"review":{"state":"automated","basis":"inferred"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.00323,"percentile":0.25122},"ssvc":{"available":true,"exploitation":"none","automatable":"no","technicalImpact":"partial"}}