Skip to content
VulniPulse
High8.8Red Hat Linux

High [CVE-2026-70427] Arbitrary file write via crafted archives and symbolic links

This high-severity Red Hat Linux advisory covers CVE-2026-70427 affecting OpenShift Developer Tools and Services.

CVE-2026-70427 Published Aug 5, 2026Updated by vendor Aug 5, 2026
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.

A flaw was found in Jenkins. Successful exploitation allows an attacker to write files to arbitrary locations on the file system, potentially leading to unauthorized data modification or system compromise.

This could result in arbitrary code execution and compromise of the Jenkins instance, for example by writing malicious scripts or plugins into the Jenkins home directory, but requires the attacker to already be able to run an agent process against the controller, limiting the attack surface to build infrastructure that is already at least partially trusted.

This is an incomplete fix of a previously disclosed issue (CVE-2026-33001). Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Weakness: CWE-59. Affected Red Hat products: OpenShift Developer Tools and Services.

Red Hat does not currently list a fixing RHSA for this CVE.

Affected versions
  • 2.575
  • 2.568.1

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Fixed versions

No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Until Jenkins is updated to a fixed version, restrict which users and systems are permitted to connect build agents to the Jenkins controller, and avoid running untrusted or externally triggered build jobs on agents that can return archives to the controller. Monitor the Jenkins controller's file system, in particular the init.groovy.d and plugins directories under the Jenkins home directory, for unauthorized changes.

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.