Arbitrary Code Execution Vulnerability in Jenkins Script Security Plugin
CVE-2026-92125

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92125?

The Jenkins Script Security Plugin, version 1415.v9a_f9b_3a_c253d and earlier, contains a vulnerability that permits attackers with sufficient permissions to define and execute sandboxed scripts. This flaw arises from the plugin's failure to adequately reject the @GroovyASTTransformationClass annotation, enabling the execution of arbitrary AST transformations during the compilation of scripts. Consequently, this loophole circumvents the sandbox protections, allowing potential execution of malicious code within the Jenkins controller's JVM environment.

Affected Version(s)

Jenkins Script Security Plugin 0 <= 1415.v9a_f9b_3a_c253d

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.