CVE-2026-92134: XSS

Published Sep 16, 2026
·
Updated

Jenkins Warnings Plugin 13.10258.va17d49a78c3b and earlier does not validate the analysis results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS) vulnerability.

Affected Software

1 affected component
Jenkins Warnings Plugin<=13.10258.va_17d49a_78c3b_

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Jenkins Warnings Plugin to a version that resolves this vulnerability.

    Fixed in 13.10258.va_17d49a_78c3b_
  2. Compensating control

    Restrict access to the Jenkins REST API endpoint that allows job configuration submission (e.g., limit Item/Configure permission) to prevent untrusted users from submitting the malicious identifier via REST.

Event History

Sep 16, 2026
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs Item/Configure permission and must be able to submit a job configuration through the REST API. This is therefore primarily relevant where untrusted or insufficiently trusted users can configure Jenkins jobs.

2

What input is used to trigger the XSS?

The attacker can set an analysis results ID to an identifier using a javascript: scheme URL. The vulnerable plugin stores this value, resulting in stored cross-site scripting.

3

Which plugin versions are affected?

Jenkins Warnings Plugin version 13.10258.va_17d49a_78c3b_ and earlier are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203