THREAT OPS › Threat News › [NVD] CVE-2026-33001 (HIGH 8.8) — Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the
[NVD] CVE-2026-33001 (HIGH 8.8) — Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the
CVE-2026-33001 CVSS: 8.8 HIGH Published: 2026-03-18T16:16:28.067
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy
Indicators of compromise
- CVE-2026-33001cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-33001