Vulnerability in Jenkins Script Security Plugin Allows Code Execution
CVE-2026-92124
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-92124?
The Jenkins Script Security Plugin, specifically version 1415.v9a_f9b_3a_c253d and earlier, is susceptible to a significant security flaw. This issue arises when the plugin checks the operations that Groovy will execute on elements read from a collection cast by a sandboxed script. The flaw occurs because the casting is performed directly on the collection rather than on the individual elements. As a result, attackers who possess the necessary permissions to run sandboxed scripts, including Pipelines, can exploit this vulnerability to evade sandbox protections and execute arbitrary code within the Jenkins controller Java Virtual Machine (JVM). This poses a serious threat to the integrity and security of Jenkins environments.
Affected Version(s)
Jenkins Script Security Plugin 0 <= 1415.v9a_f9b_3a_c253d