Jenkins Script Security Plugin Vulnerability Allows Code Execution
CVE-2026-92126

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92126?

The Jenkins Script Security Plugin prior to version 1415.v9a_f9b_3a_c253d is susceptible to a security flaw that fails to appropriately restrict @Builder annotations. This vulnerability permits users with the ability to create and execute sandboxed scripts, including those in Pipelines, to potentially run malicious code outside of the intended sandbox environment. The attack exploits the builderStrategy member, allowing an arbitrary class specified by the attacker on the classpath to be utilized, posing a significant risk to system integrity and data security. Immediate actions should be considered to mitigate exposure.

Affected Version(s)

Jenkins Script Security Plugin 0 <= 1415.v9a_f9b_3a_c253d

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.