CVE-2026-33001
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.
| Vendor | jenkins project |
| Product | jenkins |
| Ecosystems | |
| Industries | Technology |
| Published | Mar 18, 2026 |
| Last Updated | Jul 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for jenkins project jenkins
Be the first to know when new high vulnerabilities affecting jenkins project jenkins are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Jenkins Project / Jenkins
All versions affected References
jenkins.io: https://www.jenkins.io/security/advisory/2026-03-18/#SECURITY-3657 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-33001 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2448645 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33001.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:10209 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:10201 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:10211 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:10204 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:10214 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:10213 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:10215 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:10206 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:10199 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:10205