Arbitrary Code Execution Vulnerability in Jenkins Script Security Plugin
CVE-2026-92127
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-92127?
The Jenkins Script Security Plugin prior to version 1415.v9a_f9b_3a_c253d allows users with Overall/Administer privileges to inadvertently approve classpath entries when copying or updating item configurations via the REST API or CLI. This flaw can be exploited by an attacker with the ability to define classpath entries, leading to arbitrary code execution within the Jenkins controller JVM. Immediate action is recommended to mitigate potential attacks.
Affected Version(s)
Jenkins Script Security Plugin 0 <= 1415.v9a_f9b_3a_c253d