Description
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute code outside the sandbox.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The Jenkins Script Security Plugin before version 1415.v9a_f9b_3a_c253d fails to verify calls that sandboxed scripts make to methods introduced at runtime. Because the plugin does not enforce the sandbox policy on these dynamic method calls, an attacker who can author and run sandboxed scripts—such as those defined in Jenkins Pipelines—can escape the sandbox and execute arbitrary code on the Jenkins master. This ability to bypass sandbox protection endangers the confidentiality, integrity, and availability of the entire Jenkins environment.

Affected Systems

The vulnerability affects all Jenkins instances that use the Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d or earlier. Any deployment that has the plugin installed at a vulnerable version is at risk. Jenkins versions using newer releases of the plugin are not affected.

Risk and Exploitability

The CVSS score of 7.5 classifies this flaw as a high‑impact vulnerability. The EPSS score of less than 1 % indicates a low public exploitation probability; it is not listed in the CISA KEV catalog. The exploitation path requires a user with permission to create and execute sandboxed scripts—typically a role such as 'Script' or 'Pipeline' author. Based on the description, it is inferred that an attacker could embed a call to a dynamically added method within a pipeline script, thereby bypassing sandbox checks and running code outside the restricted environment. Organizations that grant script or pipeline execution privileges broadly may therefore face a significant risk.

Generated by OpenCVE AI on September 18, 2026 at 06:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the most recent Jenkins Script Security Plugin update (version 1415.v9a_f9b_3a_c253d or later).
  • If a patch is not yet available, restrict or remove the 'script' permissions from all users except administrators, limiting who can craft new pipeline scripts.
  • Disable dynamic method addition in the plugin configuration if the option exists, or temporarily force the plugin to reject runtime‑added methods.

Generated by OpenCVE AI on September 18, 2026 at 06:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins script Security
CPEs cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins
Jenkins script Security

Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Sandbox Bypass via Dynamic Method Calls in Jenkins Script Security Plugin

Thu, 17 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Script Security Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Script Security Plugin

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute code outside the sandbox.
References

Subscriptions

Jenkins Script Security
Jenkins Project Jenkins Script Security Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-16T19:46:22.899Z

Reserved: 2026-09-15T16:29:44.794Z

Link: CVE-2026-92129

cve-icon Vulnrichment

Updated: 2026-09-16T19:46:14.938Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T14:17:14.917

Modified: 2026-09-21T17:15:00.607

Link: CVE-2026-92129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:45:04Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure