CVE-2026-92126
Last modified
CVE-2026-92126 is a vulnerability of currently unknown severity. Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to execute code outside the sandbox if a suitable class is present on the classpath of the component that evaluates the script..
Description
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to execute code outside the sandbox if a suitable class is present on the classpath of the component that evaluates the script.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Jenkins Project | Jenkins Script Security Plugin | <= 1415.v9a_f9b_3a_c253d |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-92126?
How severe is CVE-2026-92126?
How do I fix CVE-2026-92126?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-92114A vulnerability was identified in a2ui-project a2ui up to 0.…5.3
- CVE-2026-9212Insufficient authentication and input validation in the list…8
- CVE-2026-92122Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and ear…8.8
- CVE-2026-92123Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and ear…8.8
- CVE-2026-92124Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and ear…8.8
- CVE-2026-92125Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and ear…8.8
- CVE-2026-92127Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and ear…8
- CVE-2026-92128Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and ear…7.5
- CVE-2026-92129Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and ear…7.5
- CVE-2026-9213A vulnerability in the affected NETGEAR gaming routers allow…8.1
- CVE-2026-92130Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and …3.1
- CVE-2026-92131Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d…4.2
Are you affected by CVE-2026-92126?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
