Description
Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Published: 2026-09-16
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting
Action: Patch Immediately
AI Analysis

Impact

The Jenkins OWASP Dependency‑Check Plugin, versions 5.6.4 and earlier, fails to escape CWE identifiers that appear in Dependency‑Check reports when they are displayed on the Jenkins user interface. Because the uncoded values are rendered directly into HTML, a malicious actor who can add a configuration item can inject JavaScript that will run in the browser of any user who views the affected job page. The vulnerability enables stored cross‑site scripting; it can lead to session hijacking, defacement, or credential theft for users with browser access to the Jenkins instance.

Affected Systems

The affected product is the Jenkins OWASP Dependency‑Check Plugin for the Jenkins Project. The flaw exists in plugin releases 5.6.4 and earlier. Any Jenkins installation that has those plugin versions installed, regardless of Jenkins core version, is at risk. The vulnerability is specific to jobs and items where users have Item/Configure permission, but affected configuration pages can be accessed by any user who can view the job.

Risk and Exploitability

The severity of the issue is reflected in a CVSS score of 8, indicating high impact. The EPSS score is below 1 percent, suggesting a low probability of widespread exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. Attackers still need the Item/Configure right to inject the malicious payload, so the attack vector is internal or requires privileged access. Once injected, the payload is executed in the victim’s browser, giving the attacker persistence and the ability to steal credentials or perform other client‑side attacks.

Generated by OpenCVE AI on September 18, 2026 at 05:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Jenkins OWASP Dependency‑Check Plugin to the latest version (5.6.5 or later).
  • Remove or restrict the Item/Configure permission from users who do not need it.
  • Validate that Jenkins core and other plugins remain compatible after the upgrade.

Generated by OpenCVE AI on September 18, 2026 at 05:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Stored XSS via Unescaped CWE Values in Dependency‑Check Plugin

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Owasp Dependency-check Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Owasp Dependency-check Plugin

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 8.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
References

Subscriptions

Jenkins Project Jenkins Owasp Dependency-check Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-16T19:08:35.313Z

Reserved: 2026-09-15T16:29:44.795Z

Link: CVE-2026-92136

cve-icon Vulnrichment

Updated: 2026-09-16T19:08:28.897Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:15.587

Modified: 2026-09-18T13:46:13.937

Link: CVE-2026-92136

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')