Sandbox Bypass Vulnerability in Jenkins Script Security Plugin
CVE-2026-92122
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-92122?
The Jenkins Script Security Plugin before version 1415.v9a_f9b_3a_c253d is susceptible to a sandbox bypass vulnerability. This flaw arises when a sandboxed script coerces a value to an interface, allowing the method invoked through a proxy to infiltrate the sandbox checks if the value inherits a method sharing a name with an interface method. Consequently, an attacker possessing the relevant permissions can exploit this weakness to execute arbitrary code within the Jenkins controller's JVM, posing a significant risk to the integrity of the system.
Affected Version(s)
Jenkins Script Security Plugin 0 <= 1415.v9a_f9b_3a_c253d