GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins: project naming strategy config lets Overall/Manage holders instantiate admin-only types

CVSS 2.7CVE-2026-70430Control plane, storage & DevOpscurated

Impact

Jenkins does not restrict which object types can be instantiated through the project naming strategy configuration, so a user holding Overall/Manage can create configuration objects that are meant to be administrator-only. This is a privilege boundary erosion inside the Jenkins controller rather than a way in: the attacker already needs a high-privilege account. It matters where Jenkins is the pipeline that builds and pushes container images to the GPU fleet, because the controller holds registry and cluster credentials and the Overall/Manage-to-administrator gap is the only thing keeping a delegated operator away from them. Scored 2.7 - real, but not a reason to interrupt a run.

Who can reach it

An authenticated Jenkins user with Overall/Manage permission. Not reachable by anonymous users or by ordinary job authors.

What to do

Update the Jenkins controller past 2.575 (weekly) or LTS 2.568.1 using the fixed release named in the 2026-08-05 security advisory; the record does not state the fixed version numbers. Applying it means restarting the controller, which aborts or queues in-flight builds - fold it into the next routine Jenkins update rather than scheduling a window for it. In the meantime, review who actually holds Overall/Manage.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.