Arbitrary File Write Vulnerability in Jenkins Robot Framework Plugin by Jenkins
CVE-2026-92137
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-92137?
The Jenkins Robot Framework Plugin versions 6.2.2 and earlier are susceptible to an arbitrary file write vulnerability. This flaw allows users with Item/Configure permissions to define an archive directory for Robot Framework report files outside the designated build directory on the Jenkins controller. As a result, an attacker could manipulate the file system by creating or replacing files with their own content, potentially leading to remote code execution. It's essential for users to ensure their plugin is updated to prevent exploitation of this vulnerability.
Affected Version(s)
Jenkins Robot Framework Plugin 0 <= 6.2.2