Stored Cross-Site Scripting Flaw in Jenkins Warnings Plugin
CVE-2026-92134

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92134?

The Jenkins Warnings Plugin prior to version 13.10258.va_17d49a_78c3b_ contains a stored cross-site scripting (XSS) vulnerability. This issue arises from insufficient validation of the analysis results ID provided through the REST API during job configuration submissions. Attackers holding Item/Configure permission can exploit this flaw by using a javascript: scheme URL, potentially allowing them to execute arbitrary scripts in the context of the user's browser.

Affected Version(s)

Jenkins Warnings Plugin 13.10223.10225.vcf001b_b_b_3a_90

Jenkins Warnings Plugin 13.10223.10225.vcf001b_b_b_3a_90

Jenkins Warnings Plugin 13.10259.v80f407cb_03a_e

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.