Vulnerability in Jenkins Script Security Plugin Allows Code Execution
CVE-2026-92124

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92124?

The Jenkins Script Security Plugin, specifically version 1415.v9a_f9b_3a_c253d and earlier, is susceptible to a significant security flaw. This issue arises when the plugin checks the operations that Groovy will execute on elements read from a collection cast by a sandboxed script. The flaw occurs because the casting is performed directly on the collection rather than on the individual elements. As a result, attackers who possess the necessary permissions to run sandboxed scripts, including Pipelines, can exploit this vulnerability to evade sandbox protections and execute arbitrary code within the Jenkins controller Java Virtual Machine (JVM). This poses a serious threat to the integrity and security of Jenkins environments.

Affected Version(s)

Jenkins Script Security Plugin 0 <= 1415.v9a_f9b_3a_c253d

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.