PT-2026-26073 · Jenkins+1 · Jenkins+1

·

CVE-2026-33001

·

Published

2026-03-18

·

Updated

2026-08-13

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Jenkins versions prior to 2.555 Jenkins LTS versions prior to 2.541.3
Description Unsafe handling of symbolic links during the extraction of .tar and .tar.gz archives allows attackers with Item/Configure permission, or those who can control agent processes, to write files to arbitrary locations on the filesystem. This action is restricted only by the file system access permissions of the user running Jenkins. Such a flaw could enable the deployment of malicious scripts or plugins on the Jenkins controller, potentially leading to unauthorized code execution.
Recommendations Update Jenkins to version 2.555 or later. Update Jenkins LTS to version 2.541.3 or later.

Fix

DoS

RCE

Link Following

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04250
BIT-JENKINS-2026-33001
CVE-2026-33001
GHSA-R6QV-FRPC-Q66C

Affected Products

Jenkins
Red Os