Description
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through the REST API or CLI, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins controller JVM.
Published: 2026-09-16
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Jenkins Script Security Plugin allows a user with overall administration rights to copy items or update them through the REST API or CLI, and in doing so it automatically approves any classpath entries defined in the configuration. Because the plugin does not perform input validation on these classpath values, an attacker can inject malicious classpaths that are loaded by the Jenkins controller JVM, leading to arbitrary code execution. This weakness corresponds to code injection (CWE‑94).

Affected Systems

The vulnerability is present in Jenkins Script Security Plugin versions 1415.v9a_f9b_3a_c253d and earlier, as identified by the Jenkins Project. All installations running those plugin versions are affected; newer releases contain the fix. The plugin is part of the Jenkins core ecosystem and is widely deployed in CI/CD pipelines.

Risk and Exploitability

The CVSS score of 8 indicates high severity, while the EPSS score of less than 1% shows low current exploitation probability but the vulnerability is not yet in the CISA KEV list. Attackers would need to act as an administrator to leverage the REST API, CLI, or GUI to copy or edit items. Given the high potential impact of arbitrary code execution in the controller JVM, the risk remains significant, especially for environments with broad admin permissions.

Generated by OpenCVE AI on September 18, 2026 at 05:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Jenkins Script Security Plugin to the latest version that contains the fix.
  • Restrict Overall/Administer permissions to trusted users and monitor API or CLI activity that copies or updates items.
  • As an interim workaround, disable automatic classpath approval in the plugin settings or manually review and remove suspicious classpath entries after item copy or update.

Generated by OpenCVE AI on September 18, 2026 at 05:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins script Security
CPEs cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins
Jenkins script Security

Fri, 18 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Script Security Plugin Classpath Injection Enables Arbitrary Code Execution

Thu, 17 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Script Security Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Script Security Plugin

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through the REST API or CLI, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins controller JVM.
References

Subscriptions

Jenkins Script Security
Jenkins Project Jenkins Script Security Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-16T19:56:22.644Z

Reserved: 2026-09-15T16:29:44.794Z

Link: CVE-2026-92127

cve-icon Vulnrichment

Updated: 2026-09-16T19:56:18.181Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T14:17:14.720

Modified: 2026-09-21T17:16:22.473

Link: CVE-2026-92127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:15:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')