Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Aug 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Inconsistent Case Handling of User and Group Names in Jenkins Allows Impersonation | |
| First Time appeared |
Jenkins Project
Jenkins Project jenkins |
|
| Weaknesses | CWE-287 | |
| Vendors & Products |
Jenkins Project
Jenkins Project jenkins |
Wed, 05 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-08-05T17:40:29.055Z
Reserved: 2026-08-04T14:13:20.602Z
Link: CVE-2026-70429
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T19:45:03Z