CVE-2026-70429: exploitation status and patch state
CVE-2026-70429
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances.
Is CVE-2026-70429 exploited?
Not in the CISA KEV catalog.
Public exploit code: none found in monitored sources.