CVE-2026-33001Disclosure(jenkins / jenkins)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch jenkins jenkins systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jenkins

Threat summary

  • Patch or workaround signal is available
  • 14 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 12 signals
  • Disclosure: 8 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 4 mentions (2026-03-19); latest day: 3
  • 14 total mentions across 8 days

Affected systems

Vendors
Products
jenkins

Deep dive

Activity timeline14 mentions / 8d
01234Mentions · 2026-03-18: 1Mentions · 2026-03-19: 4Mentions · 2026-03-20: 2Mentions · 2026-03-21: 1Mentions · 2026-03-22: 1Mentions · 2026-03-27: 1Mentions · 2026-04-12: 1Mentions · 2026-08-10: 3Patch / Workaround · 2026-03-19: 2Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-04-12: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 3Technical Details · 2026-03-20: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-27: 1Technical Details · 2026-04-12: 1Technical Details · 2026-08-10: 303-1803-1903-2003-2103-2203-2704-1208-10
Signal classification3 categories
Disclosure
857.1%
Patch
428.6%
General
214.3%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-03-181
Disclosure1
2026-03-194
Disclosure1General1Patch2
2026-03-202
General1Patch1
2026-03-211
Disclosure1
2026-03-221
Disclosure1
2026-03-271
Disclosure1
2026-04-121
Patch1
2026-08-103
Disclosure3
Full discourse14 posts
  • Gray Hats@the_yellow_fall
    Patch

    Jenkins patches critical flaws (CVE-2026-33001 & CVE-2026-33002) allowing remote code execution and full CI/CD pipeline compromise. Update to 2.555 now. #Jenkins #CyberSecurity #DevSecOps #CVE #InfoSec #RCE #Vulnerability #CICD #PatchAlert #TechNews https://securityonline.info/pipeline-poison-critical-jenkins-vulnerabilities-rce-cve-2026-33001/ https://t.co/rsITCpHxZA

    Post summary

    Jenkins has released update 2.555 to resolve two critical CVEs that allow remote code execution and compromise the CI/CD pipeline.

    060155874
    10.7K followersView on X
  • Andre Gironda@AndreGironda
    Patch

    CVE-2026-33001 , CVE-2026-33002 , 2026-03-18 Before versions 2.555, LTS 2.541.3 Jenkins does not safely handle links during extraction of tar / tgz. Crafted archives can write files to arbitrary locations leading to code execution -- https://www.jenkins.io/security/advisory/2026-03-18

    Post summary

    The advisory announces that Jenkins versions prior to 2.555 and LTS 2.541.3 are vulnerable to arbitrary file writes via crafted tar/tgz archives, leading to code execution, and that newer releases have addressed the issue.

    00050191
    3.6K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 『For archives extracted on the controller, this can result in code execution』 CVE-2026-33001、CVE-2026-33002、CVE-2026-33003、CVE-2026-33004 Jenkins Security Advisory 2026-03-18 https://www.jenkins.io/security/advisory/2026-03-18/

    Post summary

    The snippet is a brief Jenkins advisory announcing CVE‑2026‑33001 through CVE‑2026‑33004, warning that extracting archives on the controller can lead to code execution. No PoC, exploit code, or patch details are explicitly provided.

    00020450
    6.7K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Jenkins の複数の脆弱性が FIX:コントローラー上での RCE や CLI 実行などの恐れ https://iototsecnews.jp/2026/03/20/new-critical-jenkins-vulnerabilities-put-ci-cd-servers-at-risk-of-rce-exploits/ Jenkins プロジェクトが公開した、 コアシステムおよび LoadNinja プラグインに関する複数の深刻な脆弱性について解説する記事です。1 つ目の脆弱性 CVE-2026-33001 は、Jenkins コアにおけるアーカイブファイルの展開処理の不備に起因します。 具体的には、” .tar” 形式などのファイルを解凍する際、 シンボリックリンクを悪用する攻撃者に、本来のディレクトリ外へのファイル書き込みを許してしまいます。それにより、コンフィグ・ファイルやスクリプトの不正な配置が生じ、 最終的に Jenkins 上での任意のコード実行 (RCE) に至る恐れがあります。 また、 Jenkins CLI の脆弱性 CVE-2026-33002 は、 接続元の不十分な検証による DNS リバインディングを許すものであり、認証の回避が引き起こされます。さらに、LoadNinja プラグインでは、 API キーが平文で保存/表示されてしまうという管理上の不備が生じています。ご利用のチームは、ご注意ください。 #CVE202633001 #CVE202633002 #CVE202633003 #CVE202633004 #Jenkins #Vulnerability

    Post summary

    The article announces newly disclosed critical Jenkins vulnerabilities, detailing RCE risks and authentication bypasses, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    01000134
    481 followersView on X
  • ThreatCluster@threatcluster
    Patch

    Jenkins project issues Mar 18 advisory on critical bugs in core and LoadNinja plugin, incl. CVE-2026-33001 enabling RCE on CI/CD servers. Admins urged to patch controllers promptly. #RCE https://threatcluster.io/cluster/critical-jenkins-vulnerabilities-enable-rce-attacks-on-cicd--9dd62cc0

    Post summary

    An advisory warns admins about critical RCE vulnerabilities in Jenkins core and the LoadNinja plugin (CVE-2026-33001) and urges immediate patching of affected controllers.

    0001064
    105 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - Jenkins FilePath.untarFrom Symlink Bypass RCE (CVE-2026-19429) Jenkins FilePath.untarFrom() validates symlink destinations but not symlink targets, bypassing the CVE-2026-33001 patch. An attacker with Item/Configure permission can extract a malicious tar archive that plants workspace symlinks pointing to arbitrary controller paths. By targeting $JENKINS_HOME/secrets/, sensitive files like master.key and credentials.xml become readable via the workspace viewer, enabling offline AES decryption of all stored credentials and admin tokens — compromising every downstream system they protect. No patch is currently available. 👉Affected: Jenkins (core -all versions)

    Post summary

    The post discloses a new Jenkins RCE flaw, CVE-2026‑19429, caused by symlink target validation bypass, noting no patch exists and providing technical details but no proof of active exploitation or exploit code.

    00000130
    285 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19429 Jenkins FilePath.untarFrom() (all versions) validates symlink destinations but not targets, bypassing CVE-2026-33001. Any user with Item/Build access can trigger extr… https://www.cve.org/CVERecord?id=CVE-2026-19429 ----- Traducción: CVE-2026-19429 Jen… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑19429, a Jenkins FilePath.untarFrom() flaw that fails to verify symlink targets, allowing users with Item/Build permissions to trigger the vulnerability, potentially bypassing an earlier CVE.

    0000030
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19429 Jenkins FilePath.untarFrom() (all versions) validates symlink destinations but not targets, bypassing CVE-2026-33001. Any user with Item/Build access can trigger extr… https://www.cve.org/CVERecord?id=CVE-2026-19429

    Post summary

    The tweet discloses a new Jenkins vulnerability (CVE-2026-19429) involving improper symlink target validation in FilePath.untarFrom(), which may allow users with Item/Build access to trigger exploitation by bypassing a previous CVE (CVE-2026-33001).

    000001.8K
    57.9K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `Jenkins` is affected by CVE-2026-33001, a link following vulnerability enabling arbitrary file creation. Admins should review `Jenkins` advisories for patch information. #Jenkins #infosec #vulnerability https://www.pulsepatch.io/posts/cve-2026-33001-jenkins-arbitrary-file-creation

    Post summary

    The post informs that Jenkins is affected by CVE-2026-33001, a vulnerability that allows arbitrary file creation, and urges administrators to consult advisories for patch details.

    0000056
    13 followersView on X
  • 白恋黒@shirakoi_kuro
    Disclosure

    メモ:Jenkinsの重大な脆弱性により、CI/CDサーバーがリモートコード実行攻撃に晒される NIST:https://nvd.nist.gov/vuln/detail/CVE-2026-33001 Cyber Security News:https://cybersecuritynews.com/jenkins-vulnerabilities-expose-ci-cd-servers/

    Post summary

    The memo highlights Jenkins CVE‑2026‑33001 as a remote code execution flaw exposing CI/CD servers, with links to the NVD and a news article, but no PoC, exploit code, active exploitation reports, or patch details are provided.

    00000141
    56 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Jenkins ❗ CVE-2026-33002 ❗ CVE-2026-33001 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-jenkins/ https://t.co/482yFHwkJX

    Post summary

    The tweet lists two Jenkins CVEs and links to a site for more details.

    0000087
    6.6K followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    Critical Jenkins Flaws Expose CI/CD Servers to Remote Code Execution https://securityonline.info/pipeline-poison-critical-jenkins-vulnerabilities-rce-cve-2026-33001/

    Post summary

    The headline announces that critical Jenkins CVEs expose CI/CD servers to remote code execution, but the text provides no details on PoC, exploitation, patches, or active attacks.

    0000056
    300 followersView on X
  • Karma-X@Karma_X_Inc
    General

    Critical Jenkins Flaws Expose CI/CD Servers to Remote Code Execution https://securityonline.info/pipeline-poison-critical-jenkins-vulnerabilities-rce-cve-2026-33001/

    Post summary

    The post merely advertises a Jenkins vulnerability article without providing details on exploitation, mitigation, or technical specifics.

    0000067
    70 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33001 Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives… https://www.cve.org/CVERecord?id=CVE-2026-33001

    Post summary

    CVE-2026-33001 discloses that Jenkins versions prior to 2.554 (and LTS 2.541.2) fail to safely handle symbolic links during extraction of .tar/.tar.gz archives, potentially allowing crafted archives to exploit the system.

    00000133
    56.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appjenkinsjenkins---
Appjenkinsjenkins---

Explore more