Arbitrary Code Execution Vulnerability in Jenkins Script Security Plugin
CVE-2026-92125
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-92125?
The Jenkins Script Security Plugin, version 1415.v9a_f9b_3a_c253d and earlier, contains a vulnerability that permits attackers with sufficient permissions to define and execute sandboxed scripts. This flaw arises from the plugin's failure to adequately reject the @GroovyASTTransformationClass annotation, enabling the execution of arbitrary AST transformations during the compilation of scripts. Consequently, this loophole circumvents the sandbox protections, allowing potential execution of malicious code within the Jenkins controller's JVM environment.
Affected Version(s)
Jenkins Script Security Plugin 0 <= 1415.v9a_f9b_3a_c253d