Description
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from the second, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins controller JVM.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier contains a flaw that downloads a JAR file from a specified URL twice—first to confirm approval and second to load classpath entries. An attacker who can define classpath entries can manipulate the second download to inject arbitrary code, which is then executed within the Jenkins controller JVM, giving full control over the server.

Affected Systems

The vulnerability affects Jenkins Script Security Plugin versions 1415.v9a_f9b_3a_c253d and all earlier releases of the plugin. Any Jenkins instance that relies on these older plugin versions is potentially impacted.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity vulnerability and the EPSS score of less than 1% shows that exploitation is currently unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog. Exploitation would most likely occur via a remote attacker able to invoke the plugin’s functionality, allowing them to set classpath entries and trigger code execution on the Jenkins controller.

Generated by OpenCVE AI on September 18, 2026 at 05:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Jenkins Script Security Plugin to a version later than 1415.v9a_f9b_3a_c253d or the latest available patch
  • If the plugin is not required, disable it entirely to remove the attack surface
  • As an interim measure, block or restrict outbound traffic from Jenkins that may be used to download external JAR files, and configure classpath settings to permit only trusted directories

Generated by OpenCVE AI on September 18, 2026 at 05:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins script Security
CPEs cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins
Jenkins script Security

Fri, 18 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Jenkins Script Security Plugin Allows Arbitrary Code Execution via JAR Download Flaw

Thu, 17 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Script Security Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Script Security Plugin

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-494
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from the second, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins controller JVM.
References

Subscriptions

Jenkins Script Security
Jenkins Project Jenkins Script Security Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-16T19:47:26.942Z

Reserved: 2026-09-15T16:29:44.794Z

Link: CVE-2026-92128

cve-icon Vulnrichment

Updated: 2026-09-16T19:47:16.191Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T14:17:14.817

Modified: 2026-09-21T17:16:03.010

Link: CVE-2026-92128

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:15:03Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check