THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-33001 (HIGH 8.8) — Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the

[NVD] CVE-2026-33001 (HIGH 8.8) — Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the

lownvdPublished 2026-03-18

CVE-2026-33001 CVSS: 8.8 HIGH Published: 2026-03-18T16:16:28.067

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-33001