Arbitrary Code Execution Vulnerability in Jenkins Script Security Plugin
CVE-2026-92127

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92127?

The Jenkins Script Security Plugin prior to version 1415.v9a_f9b_3a_c253d allows users with Overall/Administer privileges to inadvertently approve classpath entries when copying or updating item configurations via the REST API or CLI. This flaw can be exploited by an attacker with the ability to define classpath entries, leading to arbitrary code execution within the Jenkins controller JVM. Immediate action is recommended to mitigate potential attacks.

Affected Version(s)

Jenkins Script Security Plugin 0 <= 1415.v9a_f9b_3a_c253d

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.