Description
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type but performs the cast on the collection itself, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution in the Jenkins controller JVM
Action: Immediate Patch
AI Analysis

Impact

The Jenkins Script Security Plugin (v1415.v9a_f9b_3a_c253d and earlier) incorrectly controls the operations performed by Groovy on collection elements that are cast to another type. This flaw allows a sandboxed script author to cast the collection itself to an arbitrary type, bypassing the sandbox and executing arbitrary code within the Jenkins controller JVM. The weakness results in a full remote code execution vulnerability for users who can create and run sandboxed scripts, including Pipeline authors.

Affected Systems

Jenkins Project – Jenkins Script Security Plugin, any version 1415.v9a_f9b_3a_c253d and earlier. All instances of Jenkins deployed with these plugin versions are affected.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% and absence from the CISA KEV catalog suggest a lower likelihood of exploitation today. Nevertheless, the critical risk is that an attacker with permission to write or run sandboxed Groovy scripts can execute arbitrary code in the controller JVM, compromising the entire Jenkins environment. The likely attack vector is an insider or compromised account that can upload a malicious pipeline or script, or an attacker who gains such permissions remotely. The vulnerability hinges on unauthorized sandbox escapes, so any user with script execution rights is a potential vector.

Generated by OpenCVE AI on September 18, 2026 at 06:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Jenkins Script Security Plugin to a version newer than 1415.v9a_f9b_3a_c253d.
  • Revoke or limit the "Run Groovy scripts" permission for untrusted or non‑administrative users.
  • Refactor or remove pipeline and Groovy scripts that cast collection elements to arbitrary types, ensuring only safe types are used.

Generated by OpenCVE AI on September 18, 2026 at 06:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins script Security
CPEs cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins
Jenkins script Security

Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Sandbox Escalation in Jenkins Script Security Plugin via Unchecked Collection Cast

Thu, 17 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Script Security Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Script Security Plugin

Wed, 16 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type but performs the cast on the collection itself, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
References

Subscriptions

Jenkins Script Security
Jenkins Project Jenkins Script Security Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-16T20:02:24.718Z

Reserved: 2026-09-15T16:29:44.794Z

Link: CVE-2026-92124

cve-icon Vulnrichment

Updated: 2026-09-16T20:02:18.338Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T14:17:14.383

Modified: 2026-09-21T17:30:34.140

Link: CVE-2026-92124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:45:04Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure