jenkins

8 records · 0 with a public proof-of-concept

Disclosed vulnerabilities where the NVD names jenkins as an affected vendor, highest CVSS first.

  1. HIGH 8.8CVE-2026-92125

    Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitrary AST transformation a…

    script security

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.8CVE-2026-92124

    Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type but performs the cast on the collection itself, allowing attac…

    script security

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.8CVE-2026-92123

    Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allowing attackers with permission to define and run sandboxed scri…

    script security

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 8.8CVE-2026-92122

    Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inherits a method of the same name as an interface method, allowin…

    script security

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 8.5CVE-2026-92126

    Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to execute…

    script security

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 8CVE-2026-92127

    Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through the REST API or CLI, al…

    script security

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 7.5CVE-2026-92129

    Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to byp…

    script security

    AI risk analysis on Exploit-DB.ai →

  8. HIGH 7.5CVE-2026-92128

    Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from the second, allowing attackers able to define classpath entries t…

    script security

    AI risk analysis on Exploit-DB.ai →