Description
Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS) vulnerability.
Published: 2026-09-16
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting
Action: Immediate Patch
AI Analysis

Impact

Jenkins Coverage Plugin fails to validate the coverage results ID when job configuration is submitted via the REST API. An attacker who has Item/Configure permission can supply a URL that uses the javascript: scheme as an identifier; once stored, the malicious script executes in the browser of anyone who later views the job configuration, enabling arbitrary script execution in the user's context.

Affected Systems

The vulnerability exists in Jenkins Coverage Plugin versions 3.3358.v9487dde48783 and lower, which is part of the Jenkins build automation platform.

Risk and Exploitability

The CVSS score of 8 indicates a high‑severity flaw. The EPSS score is below 1%, suggesting a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to have Item/Configure permission and to use the REST API to submit a job configuration; the stored XSS then affects all users who later view that configuration.

Generated by OpenCVE AI on September 18, 2026 at 05:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Jenkins Coverage Plugin to a version newer than 3.3358.v9487dde48783.
  • If an upgrade is not possible, restrict or remove Item/Configure permission for untrusted users and limit access to the REST API.
  • As a temporary measure, review or sanitize job configurations to ensure that coverage results IDs do not contain javascript: URLs.

Generated by OpenCVE AI on September 18, 2026 at 05:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Stored XSS via Unvalidated Coverage ID in Jenkins Coverage Plugin

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Coverage Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Coverage Plugin

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 8.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS) vulnerability.
References

Subscriptions

Jenkins Project Jenkins Coverage Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-16T19:09:17.233Z

Reserved: 2026-09-15T16:29:44.795Z

Link: CVE-2026-92135

cve-icon Vulnrichment

Updated: 2026-09-16T19:09:14.115Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:15.493

Modified: 2026-09-18T13:46:13.937

Link: CVE-2026-92135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')