LiveActive security incident?Get immediate response
CVE Record

CVE-2026-70426: In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and e...

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath.

CriticalCVSS 9Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

A Jenkins Remoting flaw lets connected agents, software running on agents, or users allowed to connect agents bypass a deserialization safety control. Successful abuse could seriously affect the Jenkins controller’s data, integrity, and availability. Exposure depends on affected versions and whether agent connectivity or permissions are available to an attacker.

Executive priority

Treat as an urgent remediation for affected Jenkins environments, especially those using externally managed, shared, or weakly trusted agents. Prioritize version verification, upgrades, agent isolation, and permission review. The critical impact warrants rapid action, although the supplied sources do not establish active exploitation.

Technical view

The Remoting deserialization fallback path resolves classes without applying the JEP-200 class filter. This permits qualifying agent-side actors to deserialize otherwise prohibited classes present on the Jenkins core classpath. The issue is classified as CWE-502 and carries CVSS 3.1 score 9.0 with high confidentiality, integrity, and availability impact.

Likely exposure

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, and Remoting 3384.v60d89463d9e0 and earlier are described as affected. Remoting 3355.3357.v931d3c992987 is explicitly excepted. Highest risk applies where agents are untrusted, agent systems are compromised, or Agent/Connect permission is broadly assigned.

Exploitation context

The supplied record is not in CISA KEV and provides no evidence of active exploitation. Exploitation requires an agent process, code execution on an agent, or Agent/Connect permission; attack complexity is rated high.

Researcher notes

The key boundary is a missing JEP-200 check in a fallback class-resolution path, limited to classes on the Jenkins core classpath. The bundle’s structured affected entries label apparent fixed versions as affected, conflicting with its prose boundaries. This analysis follows the prose description and vendor advisory reference; confirm exact status with the advisory.

Mitigation direction

  • Upgrade Jenkins to 2.576 or LTS 2.568.2, following the Jenkins advisory.
  • Upgrade Remoting to 3385.vf1123fb_515da_ or the vendor-recommended later release.
  • Restrict Agent/Connect permission to trusted identities with a documented operational need.
  • Disconnect or isolate untrusted and potentially compromised agents until upgrades are complete.

Validation and detection

  • Inventory Jenkins controller and Remoting versions against the advisory’s affected boundaries.
  • Confirm controllers run Jenkins 2.576, LTS 2.568.2, or a later vendor-approved release.
  • Confirm agents use Remoting 3385.vf1123fb_515da_ or a later vendor-approved release.
  • Audit Agent/Connect assignments and remove unnecessary access.
  • Review controller and agent logs for unexpected connections or activity; no specific indicators are provided.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-502: Code execution behavior lookup

Code execution and unsafe deserialization weaknesses often justify reviewing execution behavior and process telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-70426 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
2Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9CVSS 3.1CriticalCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H2.26CISA-ADP

Vulnerability scoring details

Base CVSS 3.1 score

9Critical
CVSS 3.1 vector shape for CVE-2026-70426Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
cvssV3_1other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Jenkins ProjectJenkins2.576, 2.568.2affected
Jenkins ProjectRemoting3385.vf1123fb_515da_, 3355.3357.v931d3c992987affected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-502 · source CWE mapping

Deserialization of Untrusted Data

Deserialization of Untrusted Data represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.