Sandbox Bypass Vulnerability in Jenkins Script Security Plugin
CVE-2026-92122

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92122?

The Jenkins Script Security Plugin before version 1415.v9a_f9b_3a_c253d is susceptible to a sandbox bypass vulnerability. This flaw arises when a sandboxed script coerces a value to an interface, allowing the method invoked through a proxy to infiltrate the sandbox checks if the value inherits a method sharing a name with an interface method. Consequently, an attacker possessing the relevant permissions can exploit this weakness to execute arbitrary code within the Jenkins controller's JVM, posing a significant risk to the integrity of the system.

Affected Version(s)

Jenkins Script Security Plugin 0 <= 1415.v9a_f9b_3a_c253d

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.