Description
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inherits a method of the same name as an interface method, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The Jenkins Script Security Plugin does not verify the method invoked through a proxy when a sandboxed Groovy script coerces a value to an interface. If the coerced value implements a method that has the same name as an interface method, the plugin allows execution of that method. This flaw lets an attacker who can author and run sandboxed scripts escape the sandbox and execute arbitrary code in the Jenkins controller JVM. The weakness is a classic missing security check (CWE‑693), offering a direct path to code execution on the host system.

Affected Systems

Any Jenkins installation running Script Security Plugin version 1415.v9a_f9b_3a_c253d or earlier is vulnerable. The plugin is part of the Jenkins ecosystem and is used to enforce sandbox constraints on Groovy scripts, including those executed within Pipelines. No specific operating system or JDK version constraints are mentioned, so any machine hosting the affected Jenkins instance is at risk.

Risk and Exploitability

The CVSS base score of 8.8 indicates a high‑severity remote code execution vulnerability. An EPSS score of less than 1% suggests exploitation is currently unlikely but the vulnerability remains present. The issue is not listed in the CISA KEV catalog. Attackers require the ability to drop and run sandboxed scripts, a privilege granted to users who author Pipelines or scripts. With such permissions, a crafted script can coerce an object with a malicious method, bypass the sandbox, and run code inside the controller JVM.

Generated by OpenCVE AI on September 18, 2026 at 05:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Jenkins Script Security Plugin to the latest fixed release (>= 1415.v9a_f9b_3a_c253d).
  • Restrict the set of users who can create or execute sandboxed scripts by applying least‑privilege access controls.
  • If an upgrade cannot be performed immediately, disable the Jenkins sandbox or the Script Security Plugin as an interim measure to prevent exploitation.

Generated by OpenCVE AI on September 18, 2026 at 05:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins script Security
CPEs cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins
Jenkins script Security

Fri, 18 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Sandbox Bypass in Jenkins Script Security Plugin Enabling Arbitrary Code Execution

Thu, 17 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Script Security Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Script Security Plugin

Wed, 16 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inherits a method of the same name as an interface method, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
References

Subscriptions

Jenkins Script Security
Jenkins Project Jenkins Script Security Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-16T20:03:55.395Z

Reserved: 2026-09-15T16:29:44.794Z

Link: CVE-2026-92122

cve-icon Vulnrichment

Updated: 2026-09-16T20:03:48.643Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T14:17:14.180

Modified: 2026-09-21T17:35:00.890

Link: CVE-2026-92122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:15:03Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure