Jenkins OWASP Dependency-Check Plugin Vulnerability Leading to Stored XSS
CVE-2026-92136
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-92136?
The OWASP Dependency-Check Plugin for Jenkins versions 5.6.4 and earlier is susceptible to a stored cross-site scripting (XSS) vulnerability. This occurs because the plugin fails to properly escape CWE values from Dependency-Check reports displayed on the Jenkins UI. Attackers with Item/Configure permissions can exploit this vulnerability to inject malicious scripts, potentially compromising the integrity of the Jenkins environment and affecting users who interact with the manipulated UI.
Affected Version(s)
Jenkins OWASP Dependency-Check Plugin 0 <= 5.6.4