Jenkins Security Advisory 2026-08-05:
- SECURITY-3911 / CVE-2026-70426: Agent-to-controller
deserialization filter bypass (Critical)
- SECURITY-3930 / CVE-2026-70427: Link following vulnerability
allows arbitrary file creation (High)
- SECURITY-3927 / CVE-2026-70428: Path traversal vulnerability in
file parameters (High)
- SECURITY-3924 / CVE-2026-70429: Improper handling of case
sensitivity allows privilege escalation (High)
- SECURITY-3916 / CVE-2026-70430: Users with Overall/Manage
permission can instantiate any types related to configuration
(Low)