CVE detail
CVE-2026-33001
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 27.1 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
14 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33001.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMar 18, 2026, 4:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2448645bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMar 18, 2026, 4:16 PM - https://access.redhat.com/security/cve/CVE-2026-33001access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 18, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:10215access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 18, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:10214access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 18, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:10213access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 18, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:10211access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 18, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:10209access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 18, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:10206access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 18, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:10205access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 18, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:10204access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 18, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:10201access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 18, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:10199access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 18, 2026, 4:16 PM No excerpt available.
Vendor Advisorywww.jenkins.ioMar 18, 2026, 4:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-15059CVSS 5.5 · Medium
Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.
- CVE-2026-71476CVSS 8.7 · High
Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded cache artifa…
- CVE-2026-13723CVSS 6.5 · Medium
A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization…
- CVE-2026-47121CVSS 6.1 · Medium
Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents containsObject:@".."` and rejects…
- CVE-2026-58414CVSS 5.5 · Medium
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_col…
- CVE-2026-50163CVSS 7.1 · High
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but re…