PT-2026-93777 · Jenkins · Warnings Plugin

CVE-2026-92134

·

Published

2026-09-16

·

Updated

2026-09-17

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Warnings Plugin versions prior to 13.10258.va 17d49a 78c3b
Description Insufficient validation of the analysis results ID occurs when a job configuration is submitted via the REST API. An attacker with Item/Configure permissions can provide a javascript: scheme URL as the identifier, leading to a stored cross-site scripting (XSS) flaw. XSS is a security issue where malicious scripts are injected into trusted websites.
Recommendations Update Jenkins Warnings Plugin to a version later than 13.10258.va 17d49a 78c3b .

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92134

Affected Products

Warnings Plugin