CVE-2026-70429

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances.
Configurations

No configuration.

History

06 Aug 2026, 16:16

Type Values Removed Values Added
CWE CWE-178
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

05 Aug 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-08-05 18:17

Updated : 2026-08-06 16:16


NVD link : CVE-2026-70429

Mitre link : CVE-2026-70429

CVE.ORG link : CVE-2026-70429


JSON object : View

Products Affected

No product.

CWE
CWE-178

Improper Handling of Case Sensitivity