Jenkins Script Security Plugin Vulnerability in Dynamic Method Execution
CVE-2026-92129
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-92129?
The Jenkins Script Security Plugin prior to version 1415.v9a_f9b_3a_c253d fails to adequately restrict calls from sandboxed scripts to dynamically added methods. This weakness could enable attackers with access to define and run scripts—such as Pipelines—to circumvent sandbox security measures, thereby executing arbitrary code beyond permitted boundaries.
Affected Version(s)
Jenkins Script Security Plugin 0 <= 1415.v9a_f9b_3a_c253d