Arbitrary File Write Vulnerability in Jenkins Robot Framework Plugin by Jenkins
CVE-2026-92137

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92137?

The Jenkins Robot Framework Plugin versions 6.2.2 and earlier are susceptible to an arbitrary file write vulnerability. This flaw allows users with Item/Configure permissions to define an archive directory for Robot Framework report files outside the designated build directory on the Jenkins controller. As a result, an attacker could manipulate the file system by creating or replacing files with their own content, potentially leading to remote code execution. It's essential for users to ensure their plugin is updated to prevent exploitation of this vulnerability.

Affected Version(s)

Jenkins Robot Framework Plugin 0 <= 6.2.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.