cvedb.io
CVE-2026-70429
UNKNOWN · CVSS n/a
EPSS exploitation probability: 0%
Published 2026-08-05T18:17:12.560 · Last modified 2026-08-05T18:17:12.560

Summary

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.