Jenkins Script Security Plugin Vulnerability Allows Code Execution
CVE-2026-92123
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-92123?
The Jenkins Script Security Plugin versions 1415.v9a_f9b_3a_c253d and earlier have a significant flaw that fails to intercept operations on a null receiver. This deficiency enables authorized users to run sandboxed scripts, including Pipelines, thereby circumventing the intended sandbox protections. As a result, attackers can exploit this vulnerability to execute arbitrary code within the Jenkins controller's JVM, posing a serious risk to affected systems.
Affected Version(s)
Jenkins Script Security Plugin 0 <= 1415.v9a_f9b_3a_c253d