{
  "threat_severity" : "Moderate",
  "public_date" : "2026-08-05T17:40:29Z",
  "bugzilla" : {
    "description" : "jenkins: Jenkins: Privilege escalation via inconsistent case sensitivity in user and group names",
    "id" : "2511690",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2511690"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-178",
  "details" : [ "Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances.", "A flaw was found in Jenkins. Due to inconsistent handling of case sensitivity in user and group names, an attacker with the ability to create new users or groups could exploit this vulnerability. By crafting user or group names that case-insensitively match existing ones, the attacker could impersonate other users or gain unauthorized permissions, leading to privilege escalation." ],
  "statement" : "Red Hat OpenShift Jenkins (ocp-tools-4) ships Jenkins core versions well below the fixed 2.568.2 LTS release and is affected. Exploitation requires an attacker who already has the ability to create new users or groups in the configured security realm, which supports Privileges Required: Low rather than None. This is consistent with how Red Hat resolved the sibling flaws from the same 2026-08-05 Jenkins security advisory, CVE-2026-70428 (arbitrary file write) and CVE-2026-70426 (remoting deserialization bypass), both of which affect the same ocp-tools-4/jenkins component and were resolved AFFECTED/DELEGATED with trackers filed.",
  "affected_release" : [ {
    "product_name" : "OpenShift Developer Tools and Services 4.12",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60247",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.12::el8",
    "package" : "ocp-tools-4/jenkins-rhel8:1786628667"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.13",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60249",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.13::el8",
    "package" : "ocp-tools-4/jenkins-rhel8:1786628681"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.14",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60248",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.14::el8",
    "package" : "ocp-tools-4/jenkins-rhel8:1786533561"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.15",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60239",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.15::el8",
    "package" : "ocp-tools-4/jenkins-rhel8:1786533565"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.16",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60251",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.16::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787125166"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.17",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60246",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.17::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787124635"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.18",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60250",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.18::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787125069"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.19",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60252",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.19::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787124632"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.20",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60259",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.20::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787124925"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.21",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60254",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.21::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787125311"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.22",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60256",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.22::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787124779"
  } ],
  "package_state" : [ {
    "product_name" : "OpenShift Developer Tools and Services",
    "fix_state" : "Affected",
    "package_name" : "jenkins",
    "cpe" : "cpe:/a:redhat:ocp_tools"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-70429\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-70429\nhttps://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3924" ],
  "name" : "CVE-2026-70429",
  "mitigation" : {
    "value" : "Restrict the ability to create new users or groups to trusted administrators; disable self-registration and public account/group creation in the configured security realm. If the realm permits non-ASCII characters in user or group names, enforce ASCII-only naming policies at the identity provider to remove the attack surface. Upgrading to Jenkins weekly 2.576 or LTS 2.568.2 fully resolves the issue.",
    "lang" : "en:us"
  },
  "csaw" : false
}