Critical Vulnerability in Jenkins Script Security Plugin Allows Arbitrary Code Execution
A critical vulnerability, CVE-2026-92124, with a CVSS score of 8.8, was discovered in the Jenkins Script Security Plugin. This vulnerability allows attackers with permission to define and run sandboxed scripts to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM. Affected versions of the plugin must be updated to prevent exploitation.