CVE-2026-92127: Jenkins Script Security Plugin vulnerability

Published Sep 16, 2026
·
Updated

Jenkins Script Security Plugin 1415.v9af9b3ac253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through the REST API or CLI, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins controller JVM.

Affected Software

1 affected component
Jenkins Script Security Plugin<=1415.v9a_f9b_3a_c253d

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Jenkins Script Security Plugin to a version that resolves this vulnerability.

    Fixed in 1415.v9a_f9b_3a_c253d
  2. Compensating control

    Restrict access to the Jenkins REST API/CLI and copying/updating item configurations to trusted administrators (limit users who have Overall/Administer permission) until the Script Security Plugin is upgraded.

Event History

Sep 16, 2026
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description

Frequently Asked Questions

1

Who is exposed to this issue?

Jenkins installations using Script Security Plugin 1415.v9a_f9b_3a_c253d or earlier are exposed when item configurations can contain classpath entries and an Overall/Administer user copies the item or updates its configuration through the REST API or CLI.

2

What does an attacker need to exploit it?

An attacker must be able to define classpath entries in an item configuration. Exploitation then depends on an Overall/Administer user copying that item or updating its configuration through the REST API or CLI.

3

What is the impact of successful exploitation?

An attacker can execute arbitrary code in the context of the Jenkins controller JVM.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203