---
id: CVE-2026-70430
title: >-
  Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types
  of objects that can be instantiated as part of the project naming strategy
  configuration, allowing attackers with Overall/Manage permission to
  instantiate arb…
summary: >-
  Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types
  of objects that can be instantiated as part of the project naming strategy
  configuration, allowing attackers with Overall/Manage permission to
  instantiate arb…
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-284
vendor: jenkins
product: jenkins
affected:
  - jenkins < 2.568.2
  - jenkins < 2.576
patched:
  - jenkins 2.576
published: '2026-08-05'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:04:05.760'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-70430'
references:
  - url: 'https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3916'
    label: jenkinsci-cert@googlegroups.com
tags:
  - nvd
epss: 0.00311
epssPercentile: 0.21393
ingestedAt: '2026-09-08T20:10:03.156Z'
---

## Overview

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.

## Affected

- `jenkins < 2.568.2`
- `jenkins < 2.576`

## Remediation

Upgrade past the affected range:

- `jenkins 2.576`
