CVE-2026-19429Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-08-10); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-10: 3Mentions · 2026-08-12: 1Patch / Workaround · 2026-08-10: 1Patch / Workaround · 2026-08-12: 1Technical Details · 2026-08-10: 3Technical Details · 2026-08-12: 108-1008-12
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-103
Disclosure3
2026-08-121
Patch1
Full discourse4 posts
  • Merge News@mergenewsapp
    Patch

    Critical Jenkins flaw (CVE-2026-19429) allows arbitrary file creation via TAR archives. Update now to secure your CI/CD pipelines. #jenkins #cve #security #cicd

    Post summary

    The post highlights a critical Jenkins vulnerability (CVE-2026-19429) that permits arbitrary file creation via TAR archives and urges users to apply a patch or update to protect their CI/CD pipelines.

    0000026
    41 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - Jenkins FilePath.untarFrom Symlink Bypass RCE (CVE-2026-19429) Jenkins FilePath.untarFrom() validates symlink destinations but not symlink targets, bypassing the CVE-2026-33001 patch. An attacker with Item/Configure permission can extract a malicious tar archive that plants workspace symlinks pointing to arbitrary controller paths. By targeting $JENKINS_HOME/secrets/, sensitive files like master.key and credentials.xml become readable via the workspace viewer, enabling offline AES decryption of all stored credentials and admin tokens — compromising every downstream system they protect. No patch is currently available. 👉Affected: Jenkins (core -all versions)

    Post summary

    A new Jenkins RCE via symlink bypass (CVE‑2026‑19429) is disclosed with technical details, noting no patch yet, but no PoC or live exploitation evidence.

    00000130
    285 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19429 Jenkins FilePath.untarFrom() (all versions) validates symlink destinations but not targets, bypassing CVE-2026-33001. Any user with Item/Build access can trigger extr… https://www.cve.org/CVERecord?id=CVE-2026-19429 ----- Traducción: CVE-2026-19429 Jen… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-19429, describing how Jenkins’ `FilePath.untarFrom()` improperly validates symlink destinations, allowing users with Item/Build access to exploit the flaw. No PoC, exploit code, patch, or evidence of live exploitation is provided.

    0000030
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19429 Jenkins FilePath.untarFrom() (all versions) validates symlink destinations but not targets, bypassing CVE-2026-33001. Any user with Item/Build access can trigger extr… https://www.cve.org/CVERecord?id=CVE-2026-19429

    Post summary

    The post announces a Jenkins vulnerability where symlink targets are not validated, enabling users with Item/Build rights to exploit it, and links to the CVE record for more details.

    000001.8K
    57.9K followersView on X

Explore more