Arbitrary Code Execution Vulnerability in Jenkins Script Security Plugin
CVE-2026-92128
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-92128?
The Jenkins Script Security Plugin, versions 1415.v9a_f9b_3a_c253d and prior, is susceptible to an arbitrary code execution vulnerability. This issue arises from the plugin downloading a JAR file specified by URL twice. The first download is approved, while the subsequent download allows the attacker to manipulate the classpath entries, leading to the execution of arbitrary code within the Jenkins controller JVM context. This flaw poses a significant risk, enabling attackers to exploit the plugin's functionality to execute malicious code.
Affected Version(s)
Jenkins Script Security Plugin 0 <= 1415.v9a_f9b_3a_c253d