PT-2026-68261 · Jenkins · Remoting+1
CVE-2026-70426
·
Published
2026-08-05
·
Updated
2026-08-17
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Remoting versions prior to 3384.v60d89463d9e0 (excluding version 3355.3357.v931d3c992987)
Jenkins versions prior to 2.576
Jenkins LTS versions prior to 2.568.2
Description
The JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation. This allows agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath. JEP-200 is a Java Enhancement Proposal that introduces a mechanism to filter incoming serialized data to prevent the deserialization of unauthorized classes.
Recommendations
Update Remoting to a version newer than 3384.v60d89463d9e0, ensuring version 3355.3357.v931d3c992987 is not used if it was previously considered a fix.
Update Jenkins to version 2.576 or later.
Update Jenkins LTS to version 2.568.2 or later.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Remoting