{"id":"BIT-jenkins-2026-70428","details":"Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.","aliases":["CVE-2026-70428"],"modified":"2026-09-09T09:30:04.547902535Z","published":"2026-08-17T05:44:40.030Z","database_specific":{"severity":"Medium","cpes":["cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:maven:*:*"]},"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70428"},{"type":"ADVISORY","url":"https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3927"}],"affected":[{"package":{"name":"jenkins","ecosystem":"Bitnami","purl":"pkg:bitnami/jenkins"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.568.2"},{"introduced":"2.569.0"},{"fixed":"2.576.0"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/jenkins/BIT-jenkins-2026-70428.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}],"schema_version":"1.9.0"}