Jenkins OWASP Dependency-Check Plugin Vulnerability Leading to Stored XSS
CVE-2026-92136

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92136?

The OWASP Dependency-Check Plugin for Jenkins versions 5.6.4 and earlier is susceptible to a stored cross-site scripting (XSS) vulnerability. This occurs because the plugin fails to properly escape CWE values from Dependency-Check reports displayed on the Jenkins UI. Attackers with Item/Configure permissions can exploit this vulnerability to inject malicious scripts, potentially compromising the integrity of the Jenkins environment and affecting users who interact with the manipulated UI.

Affected Version(s)

Jenkins OWASP Dependency-Check Plugin 0 <= 5.6.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.