PT-2026-68261 · Jenkins · Remoting+1

CVE-2026-70426

·

Published

2026-08-05

·

Updated

2026-08-17

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Remoting versions prior to 3384.v60d89463d9e0 (excluding version 3355.3357.v931d3c992987) Jenkins versions prior to 2.576 Jenkins LTS versions prior to 2.568.2
Description The JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation. This allows agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath. JEP-200 is a Java Enhancement Proposal that introduces a mechanism to filter incoming serialized data to prevent the deserialization of unauthorized classes.
Recommendations Update Remoting to a version newer than 3384.v60d89463d9e0, ensuring version 3355.3357.v931d3c992987 is not used if it was previously considered a fix. Update Jenkins to version 2.576 or later. Update Jenkins LTS to version 2.568.2 or later.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2026-70426
CVE-2026-70426

Affected Products

Jenkins
Remoting