CVE-2026-70426
Published:August 05, 2026
Updated:August 06, 2026
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath.
Affected Packages
https://github.com/jenkinsci/remoting.git (GITHUB):
Affected version(s) =3384.v60d89463d9e0 <3385.vf1123fb_515da_Fix Suggestion:
Update to version 3385.vf1123fb_515da_org.jenkins-ci.main:remoting (JAVA):
Affected version(s) >=1.396 <3355.3357.v931d3c992987Fix Suggestion:
Update to version 3355.3357.v931d3c992987org.jenkins-ci.main:jenkins-core (JAVA):
Affected version(s) >=1.396 <2.568.2Fix Suggestion:
Update to version 2.568.2org.jenkins-ci.main:jenkins-core (JAVA):
Affected version(s) >=2.569 <2.576Fix Suggestion:
Update to version 2.576org.jenkins-ci.main:remoting (JAVA):
Affected version(s) >=3383.vc8881d4b_0e76 <3385.vf1123fb_515da_Fix Suggestion:
Update to version 3385.vf1123fb_515da_Related Resources (1)
Do you need more information?
Contact UsCVSS v4
Base Score:
9.5
Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
HIGH
Vulnerable System Integrity
HIGH
Vulnerable System Availability
HIGH
Subsequent System Confidentiality
HIGH
Subsequent System Integrity
HIGH
Subsequent System Availability
HIGH
CVSS v3
Base Score:
9
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
Weakness Type (CWE)
Deserialization of Untrusted Data