216.73.216.233

CVE-2026-33001

· Published 18/03/2026 16:16 · Modified 19/03/2026 14:16

Labels: CVE-2026-33001 2026-03-18CVE-2026-33001CWE-59[email protected]

Essential information

Published
18/03/2026 16:16
Modified
19/03/2026 14:16
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
jenkins / jenkins cpe:2.3:a:jenkins:jenkins:2.554:*:*:*:*:*:*:*
jenkins / jenkins cpe:2.3:a:jenkins:jenkins:<2.541.2:*:*:*:*:*:*:*

References