PT-2026-93778 · Jenkins · Coverage Plugin

CVE-2026-92135

·

Published

2026-09-16

·

Updated

2026-09-17

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Coverage Plugin versions 3.3358.v9487dde48783 and earlier
Description Insufficient validation of the coverage results ID occurs when a job configuration is submitted via the REST API. An attacker with Item/Configure permissions can provide a javascript: scheme URL as the identifier, leading to stored cross-site scripting (XSS), where malicious scripts are permanently stored on the server and executed in the browser of other users.
Recommendations Update Jenkins Coverage Plugin to a version later than 3.3358.v9487dde48783.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92135

Affected Products

Coverage Plugin