GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins Script Security Plugin (classpath entry approval): Script Security normally requires an administrator to

CVSS 8.0CVE-2026-92127Control plane, storage & DevOpscurated

Impact

Script Security normally requires an administrator to approve a Groovy classpath entry before it can be used. In versions 1415.v9af9b3ac253d and earlier the approval is granted automatically when a user with Overall/Administer copies an item, or when the configuration is updated through the REST API or the CLI. An attacker who can define classpath entries in a job configuration therefore gets arbitrary code execution inside the Jenkins controller JVM. On a build fleet that drives GPU cluster deployments, the controller usually holds registry credentials, kubeconfigs and signing keys, so controller RCE converts directly into the ability to push images and manifests that land on GPU nodes.

Who can reach it

A user who can define classpath entries in an item configuration, combined with an Overall/Administer user copying that item or submitting the configuration via REST API or CLI. Authenticated access to the Jenkins controller is required; the admin action supplies the trigger.

What to do

Update the Script Security Plugin past 1415.v9af9b3ac253d via the Jenkins update center and restart the controller; plugin updates on the controller mean a short controller outage while builds are queued, no agent or GPU node action. Until then, review the pending and approved script-approval list for classpath entries that were never approved by a human, and avoid copying items or pushing job configs through the API/CLI. The advisory does not name a configuration-only mitigation.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.