Tag

#Jenkins

newsHIGH 8.8

Critical Vulnerability in Jenkins Script Security Plugin Allows Arbitrary Code Execution

A critical vulnerability, CVE-2026-92124, with a CVSS score of 8.8, was discovered in the Jenkins Script Security Plugin. This vulnerability allows attackers with permission to define and run sandboxed scripts to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM. Affected versions of the plugin must be updated to prevent exploitation.

1 source
articleHIGH 8.8

Critical Vulnerability in Jenkins Script Security Plugin Allows Sandbox Bypass and Code Execution

A critical vulnerability, CVE-2026-92123, with a CVSS score of 8.8, was discovered in the Jenkins Script Security Plugin. This vulnerability allows attackers with permission to define and run sandboxed scripts to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM. The vulnerability affects Jenkins Script Security Plugin versions 1415.v9a_f9b_3a_c253d and earlier. Organizations using affected versions should immediately apply the provided patch to prevent potential exploitation.

1 source
newsHIGH 8.8

Critical Vulnerability in Jenkins OWASP ZAP Plugin Allows Arbitrary Code Execution

A critical vulnerability (CVE-2026-57301) with a CVSS score of 8.8 has been discovered in the Jenkins OWASP ZAP Plugin, affecting versions 1.0.7 and earlier. This vulnerability allows attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller. Immediate action is required to update to a patched version.

1 source
articleHIGH 8.8

Critical Vulnerability in Jenkins External Workspace Manager Plugin Allows Remote Code Execution

A critical vulnerability, CVE-2026-57296, with a CVSS score of 8.8, was discovered in the Jenkins External Workspace Manager Plugin. This vulnerability allows attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, potentially leading to remote code execution. The plugin versions 1.3.2 and earlier are affected. Organizations using this plugin are urged to update to the latest version to mitigate this vulnerability.

1 source