CVE-2026-27099: XSS
Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or Agent/Disconnect permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27099?
CVE-2026-27099 is categorized as a stored cross-site scripting (XSS) vulnerability with a medium severity rating.
How does CVE-2026-27099 affect Jenkins?
CVE-2026-27099 allows attackers to execute malicious scripts by exploiting the unescaped user-provided description in the 'Mark temporarily offline' feature.
Who is at risk for CVE-2026-27099?
Users of Jenkins versions 2.483 through 2.550 and LTS 2.492.1 through 2.541.1 are vulnerable to CVE-2026-27099.
How do I fix CVE-2026-27099?
To mitigate CVE-2026-27099, update your Jenkins instance to version 2.551 or later.
What versions of Jenkins are affected by CVE-2026-27099?
CVE-2026-27099 affects Jenkins from version 2.483 to 2.550 and LTS from 2.492.1 to 2.541.1.