Description
Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content, which can lead to remote code execution.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Jenkins Robot Framework Plugin versions 6.2.2 and earlier fails to verify that the directory used to store Robot Framework report archives is within the Jenkins workspace. This omission allows a user with Item/Configure permission to write arbitrary files with chosen content to the Jenkins controller filesystem. An attacker could place malicious executables or scripts in privileged locations, resulting in the ability to execute code remotely and compromise the entire Jenkins environment.

Affected Systems

Jenkins Project users running Jenkins Robot Framework Plugin 6.2.2 or earlier are affected. The vulnerability is present in the Robot Framework Plugin distributed by the Jenkins Project and targets any system where the plugin is installed without a newer, patched version.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and despite an EPSS score of less than 1 %, the bug can be exploited remotely by any authorized user with Item/Configure rights. Because the attacker can create or replace files on the controller, exploitation bypasses authentication but requires legitimate workspace permissions. The vulnerability is not listed in CISA KEV, but organizations already prioritizing secure Jenkins configurations should consider it priority because of the potential for remote code execution.

Generated by OpenCVE AI on September 18, 2026 at 05:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Jenkins Robot Framework Plugin to the latest version released by the Jenkins Project
  • If immediate upgrade is not possible, restrict Item/Configure permissions to only trusted administrators or remove the permission from users that do not need to configure plugins
  • Verify that the report archive directory is confined within the Jenkins workspace or a dedicated safe directory to prevent arbitrary file writes

Generated by OpenCVE AI on September 18, 2026 at 05:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unchecked File Writes in Jenkins Robot Framework Plugin

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Robot Framework Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Robot Framework Plugin

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content, which can lead to remote code execution.
References

Subscriptions

Jenkins Project Jenkins Robot Framework Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-16T19:07:51.105Z

Reserved: 2026-09-15T16:29:44.795Z

Link: CVE-2026-92137

cve-icon Vulnrichment

Updated: 2026-09-16T19:07:43.978Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:15.683

Modified: 2026-09-18T13:46:13.937

Link: CVE-2026-92137

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:15:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')