CVE-2026-92128: Jenkins Script Security Plugin vulnerability

Published Sep 16, 2026
·
Updated

Jenkins Script Security Plugin 1415.v9af9b3ac253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from the second, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins controller JVM.

Affected Software

1 affected component
Jenkins Script Security Plugin<=1415.v9a_f9b_3a_c253d

Event History

Sep 16, 2026
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be able to define classpath entries used by the Jenkins Script Security Plugin. Successful exploitation can execute arbitrary code in the context of the Jenkins controller JVM.

2

What versions are affected?

Jenkins Script Security Plugin version 1415.v9a_f9b_3a_c253d and earlier are affected.

3

What is the underlying approval bypass?

The plugin downloads a JAR from the specified URL twice. It confirms approval for the first download but loads classpath entries from the second download, allowing the approved content to differ from the content ultimately loaded.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203