Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Oracle Solaris CVE-2024-21013 Flaw Lets Attackers Remotely Control Servers
August 6, 2026
Canadian Man Pleads Guilty to Hacking US Cloud Storage Provider
August 6, 2026
Critical Jenkins CVE-2024-28973 Lets Attackers Run Code on Controllers
August 6, 2026
Home/CyberSecurity News/Critical Jenkins CVE-2024-28973 Lets Attackers Run Code on Controllers
CyberSecurity News

Critical Jenkins CVE-2024-28973 Lets Attackers Run Code on Controllers

Key Takeaways A critical vulnerability, CVE-2026-70426, has been identified in Jenkins, potentially allowing remote code execution on controllers. The flaw impacts Jenkins 2.575 and earlier, along...

Marcus Rodriguez
Marcus Rodriguez
August 6, 2026 3 Min Read
3 0

Key Takeaways

  • A critical vulnerability, CVE-2026-70426, has been identified in Jenkins, potentially allowing remote code execution on controllers.
  • The flaw impacts Jenkins 2.575 and earlier, along with Jenkins LTS 2.568.1 and earlier, specifically within the Remoting library.
  • Attackers can bypass a security filter during agent-to-controller communication to deserialize malicious Java objects.
  • Successful exploitation could grant attackers full control over the Jenkins controller, exposing sensitive data and compromising software supply chains.
  • Patches are available in Jenkins 2.576 and Jenkins LTS 2.568.2, and immediate upgrades are strongly recommended.

Jenkins has disclosed a severe security vulnerability that could enable attackers to execute arbitrary code on Jenkins controllers. This critical flaw circumvents a crucial security filter designed to protect agent-to-controller communications.

Table Of Content

  • Key Takeaways
  • Vulnerability Details
  • Jenkins Code Execution Vulnerability Explained
  • What You Should Do

Vulnerability Details

Designated as CVE-2026-70426, this vulnerability carries a Critical CVSS severity rating. It affects Jenkins installations utilizing specific vulnerable versions of the Remoting library. Affected Jenkins versions include 2.575 and earlier, as well as Jenkins LTS 2.568.1 and earlier. The vulnerability is present in Remoting versions 3384.v60d89463d9e0 and older, with the exception of version 3355.3357.v931d3c992987.

The Jenkins Remoting library, often distributed as agent.jar or remoting.jar, facilitates communication between the central Jenkins controller and its connected build agents. This communication relies on the serialization and deserialization of Java objects. To mitigate the inherent risks of Java deserialization vulnerabilities, which can lead to arbitrary code execution, Jenkins implements the JEP-200 class filter to scrutinize objects transmitted over a Remoting channel.

Jenkins Code Execution Vulnerability Explained

The JEP-200 filter is intended to prevent the deserialization of potentially unsafe classes by the Jenkins controller. However, researchers discovered that this critical filter was not applied when classes were resolved via a fallback path within the Remoting deserialization process. This oversight creates a bypass, allowing malicious actors to exploit the system.

An attacker capable of controlling an agent process, achieving code execution on an existing agent, or possessing the Jenkins Agent/Connect permission can leverage this flaw. By doing so, they can deserialize specific Java classes that should have been blocked by the JEP-200 filter, leading to unauthorized code execution on the Jenkins controller. The Jenkins controller is typically the most sensitive component within a Jenkins environment, making this a highly impactful vulnerability.

The scope of exploitable classes is limited to those already present on the Jenkins core classpath, including classes bundled with Jenkins itself and those part of the Java platform. Dependencies bundled within plugins are not deserialized through this vulnerable fallback path, which somewhat reduces the overall attack surface. Nevertheless, achieving controller-level code execution poses a severe risk, as a compromised controller can expose sensitive assets such as source code, secrets, build credentials, deployment keys, and critical software supply chain pipelines.

Jenkins addressed the vulnerability in advisory SECURITY-3911 with the releases of Jenkins 2.576 and Jenkins LTS 2.568.2. These updates include a revised Remoting library that ensures the JEP-200 class filter is consistently enforced, even when the fallback deserialization path is utilized. The flaw was initially reported via the European Commission’s Jenkins Bug Bounty Program.

What You Should Do

  • Immediately upgrade Jenkins controllers and agents to Jenkins 2.576 or Jenkins LTS 2.568.2, or newer patched versions.
  • Review and restrict the Agent/Connect permission, limiting its assignment to only trusted users, service accounts, and systems.
  • Isolate and monitor untrusted build agents, preventing them from accessing sensitive internal network resources.
  • For environments where an immediate upgrade is not feasible, apply the temporary workaround detailed in the Jenkins SECURITY-3911-3930 GitHub repository. Ensure this workaround is treated as a temporary measure until a full patch can be deployed.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Linux Kernel Bridge Vulnerability Lets Attackers Crash Systems, Execute Code

Next Post

Canadian Man Pleads Guilty to Hacking US Cloud Storage Provider

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OWASP Releases Top 10 for Securing Generative AI LLM Applications
August 6, 2026
OpenAI Agents Uncover Critical Zero-Day Vulnerability
August 6, 2026
Meta AI Model Exploited to Hack Third-Party System
August 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us