Stored Cross-Site Scripting Vulnerability in Jenkins Coverage Plugin
CVE-2026-92135
Currently unrated
What is CVE-2026-92135?
The Jenkins Coverage Plugin prior to version 3.3358.v9487dde48783 does not properly validate coverage result IDs when job configurations are submitted via the REST API. This oversight can be exploited by attackers with Item/Configure permission, who may inject a malicious javascript: scheme URL as the identifier, leading to a stored cross-site scripting (XSS) vulnerability. Attackers leveraging this flaw can execute arbitrary JavaScript code in the context of a user's browser session, potentially compromising user data and application integrity.
Affected Version(s)
Jenkins Coverage Plugin 3.3325.3327.v26c59e218691
Jenkins Coverage Plugin 3.3325.3327.v26c59e218691
Jenkins Coverage Plugin 3.3361.v0626103a_67e6