Stored Cross-Site Scripting Vulnerability in Jenkins Coverage Plugin
CVE-2026-92135

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92135?

The Jenkins Coverage Plugin prior to version 3.3358.v9487dde48783 does not properly validate coverage result IDs when job configurations are submitted via the REST API. This oversight can be exploited by attackers with Item/Configure permission, who may inject a malicious javascript: scheme URL as the identifier, leading to a stored cross-site scripting (XSS) vulnerability. Attackers leveraging this flaw can execute arbitrary JavaScript code in the context of a user's browser session, potentially compromising user data and application integrity.

Affected Version(s)

Jenkins Coverage Plugin 3.3325.3327.v26c59e218691

Jenkins Coverage Plugin 3.3325.3327.v26c59e218691

Jenkins Coverage Plugin 3.3361.v0626103a_67e6

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.