All verified exploits

CVE-2026-33001 Arbitrary File Write via Symlink in Tar Extraction

Deterministic high Jenkins Added cve-verified-cve-2026-33001

Detects Jenkins instances running version 2.554 or earlier (weekly) or LTS 2.541.2 or earlier where symbolic links in .tar/.tar.gz archives are followed during extraction, allowing files to be written to arbitrary filesystem locations. Attackers with Item/Configure permission can achieve remote code execution by planting Groovy init scripts. Update to Jenkins 2.555 or LTS 2.541.3.

Is your app exploitable through CVE-2026-33001?

Scan your domain free