Database/Control plane, storage & DevOps
Jenkins: project naming strategy config lets Overall/Manage holders instantiate admin-only types
Impact
Jenkins does not restrict which object types can be instantiated through the project naming strategy configuration, so a user holding Overall/Manage can create configuration objects that are meant to be administrator-only. This is a privilege boundary erosion inside the Jenkins controller rather than a way in: the attacker already needs a high-privilege account. It matters where Jenkins is the pipeline that builds and pushes container images to the GPU fleet, because the controller holds registry and cluster credentials and the Overall/Manage-to-administrator gap is the only thing keeping a delegated operator away from them. Scored 2.7 - real, but not a reason to interrupt a run.
Who can reach it
An authenticated Jenkins user with Overall/Manage permission. Not reachable by anonymous users or by ordinary job authors.
What to do
Update the Jenkins controller past 2.575 (weekly) or LTS 2.568.1 using the fixed release named in the 2026-08-05 security advisory; the record does not state the fixed version numbers. Applying it means restarting the controller, which aborts or queues in-flight builds - fold it into the next routine Jenkins update rather than scheduling a window for it. In the meantime, review who actually holds Overall/Manage.
References
Related entries
- Sunbird Power IQ 9.2.0 API: Error-based SQL injection through an outdated API endpoint with missing input validationCVE-2025-55703 · Sunbird Power IQ 9.2.0 APILow
- Lenovo ThinkSystem SR670 V2 (shipped in Manufacturing Mode): SR670 V2 servers built between roughly June 2021 and JulyCVE-2024-23591 · Lenovo ThinkSystem SR670 V2 (shipped in Manufacturing Mode)Low
- Linuxfabrik monitoring plugins: symlink attack on predictable /tmp SQLite caches lets a local user write as rootCVE-2026-53759 · linuxfabrik-lib db_sqlite.py (Monitoring Plugins cache databases in /tmp)Low
- QCT (Quanta Cloud Technology) server security centre: QCT firmware is unmeasurable from public data despiteNCVD-2026-012-qct-quanta-cloud-technology-serv · QCT (Quanta Cloud Technology) server security centreUnscored
- Supermicro's public security advisory portal itself: An operator cannot programmatically track Supermicro firmwareNCVD-2026-013-supermicro-s-public-security-adv · Supermicro's public security advisory portal itselfUnscored
- Tyan / MiTAC Computing PSIRT: For Tyan, this vendor's firmware is unmeasurable from public dataNCVD-2026-014-tyan-mitac-computing-psirt · Tyan / MiTAC Computing PSIRTUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.