Description
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Jenkins Script Security Plugin prevents interception of operations that target a null receiver, including method calls, property accesses, and array indexing. This omission allows users who can define and run sandboxed scripts, such as Jenkins Pipelines, to bypass the sandbox mechanism and execute arbitrary code with the full privileges of the Jenkins controller JVM, thereby compromising confidentiality, integrity, and availability of the system.

Affected Systems

The Jenkins Script Security Plugin version 1415.v9a_f9b_3a_c253d or any earlier release is affected. The vulnerability applies to the Jenkins Project’s Script Security Plugin, which is used to sandbox Groovy scripts in Jenkins pipelines.

Risk and Exploitability

The CVSS score of 8.8 classifies this issue as high severity, but the EPSS score of less than 1% indicates a low probability of exploitation at this time. It is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is an authorized Jenkins user who has the ability to create and execute sandboxed scripts; such a user can exploit the null receiver bypass to run malicious code on the controller. Successful exploitation would grant the attacker full control of the Jenkins instance.

Generated by OpenCVE AI on September 18, 2026 at 05:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Jenkins Script Security Plugin to a version newer than 1415.v9a_f9b_3a_c253d, which includes a fix for the null receiver bypass.
  • Immediately restrict the set of users allowed to create or run sandboxed scripts to only those who absolutely need this capability.
  • If possible, disable or remove the Jenkins Script Security Plugin sandbox when it is not required for your pipelines, or enforce additional security controls such as script approval to prevent malicious code execution.

Generated by OpenCVE AI on September 18, 2026 at 05:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins script Security
CPEs cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins
Jenkins script Security

Fri, 18 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Bypass of Null Receiver in Jenkins Script Security Plugin Allows Remote Code Execution

Thu, 17 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Script Security Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Script Security Plugin

Wed, 16 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
References

Subscriptions

Jenkins Script Security
Jenkins Project Jenkins Script Security Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-16T20:03:24.180Z

Reserved: 2026-09-15T16:29:44.794Z

Link: CVE-2026-92123

cve-icon Vulnrichment

Updated: 2026-09-16T20:03:05.799Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T14:17:14.290

Modified: 2026-09-21T17:33:17.400

Link: CVE-2026-92123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:15:03Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure