Arbitrary Code Execution Vulnerability in Jenkins Script Security Plugin
CVE-2026-92128

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92128?

The Jenkins Script Security Plugin, versions 1415.v9a_f9b_3a_c253d and prior, is susceptible to an arbitrary code execution vulnerability. This issue arises from the plugin downloading a JAR file specified by URL twice. The first download is approved, while the subsequent download allows the attacker to manipulate the classpath entries, leading to the execution of arbitrary code within the Jenkins controller JVM context. This flaw poses a significant risk, enabling attackers to exploit the plugin's functionality to execute malicious code.

Affected Version(s)

Jenkins Script Security Plugin 0 <= 1415.v9a_f9b_3a_c253d

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.