{"id":"CVE-2026-70429","title":"Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters t…","summary":"Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters t…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-178"],"vendor":"jenkins","product":"jenkins","affected":["jenkins < 2.568.2","jenkins < 2.576"],"patched":["jenkins 2.576"],"published":"2026-08-05","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:10:08.597","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-70429","references":[{"url":"https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3924","label":"jenkinsci-cert@googlegroups.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-70429.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-70429"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2511690"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-70429"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70429"},{"url":"https://access.redhat.com/errata/RHSA-2026:60247"},{"url":"https://access.redhat.com/errata/RHSA-2026:60249"},{"url":"https://access.redhat.com/errata/RHSA-2026:60248"},{"url":"https://access.redhat.com/errata/RHSA-2026:60239"},{"url":"https://access.redhat.com/errata/RHSA-2026:60251"},{"url":"https://access.redhat.com/errata/RHSA-2026:60246"},{"url":"https://access.redhat.com/errata/RHSA-2026:60250"},{"url":"https://access.redhat.com/errata/RHSA-2026:60252"},{"url":"https://access.redhat.com/errata/RHSA-2026:60259"},{"url":"https://access.redhat.com/errata/RHSA-2026:60254"},{"url":"https://access.redhat.com/errata/RHSA-2026:60256"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00236,"epssPercentile":0.14912,"ingestedAt":"2026-09-08T21:11:12.268Z","scores":{"nvd":6.5,"vendor":6.8},"slug":"CVE-2026-70429","body":"## Overview\n\nJenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances.\n\n## Affected\n\n- `jenkins < 2.568.2`\n- `jenkins < 2.576`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `jenkins 2.576`\n\n## Vendor advisories\n\n- **RHSA-2026:60247** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.12 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60247)\n- **RHSA-2026:60249** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.13 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60249)\n- **RHSA-2026:60248** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.14 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60248)\n- **RHSA-2026:60239** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.15 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60239)\n- **RHSA-2026:60251** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.16 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60251)\n- **RHSA-2026:60246** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.17 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60246)\n- **RHSA-2026:60250** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.18 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60250)\n- **RHSA-2026:60252** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.19 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60252)\n- **RHSA-2026:60259** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.20 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60259)\n- **RHSA-2026:60254** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.21 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60254)\n- **RHSA-2026:60256** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.22 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60256)\n- **Red Hat VEX** · Moderate · affected: OpenShift Developer Tools and Services · no fix planned: OpenShift Developer Tools and Services · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-70429.json)","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}