Skip to content

CVE lookup

CVE-2026-70426

Pruva has a verified reproduction for CVE-2026-70426: Jenkins Remoting JEP-200 deserialization filter bypass (SECURITY-3911): unfiltered ClassNotFoundException fallback in MultiClassLoaderSerializer.resolveClass and ObjectInputStreamEx.resolveClass lets agents deserialize blocked core-classpath classes on the controller. The canonical evidence record is REPRO-2026-00322.

REPRO

REPRO-2026-00322

Package

Unknown

Severity

CRITICAL

Status

published