GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins Script Security Plugin: approved JAR is re-downloaded, letting a second payload load into the controller

CVSS 7.5CVE-2026-92128Control plane, storage & DevOpscurated

Impact

The plugin fetches a classpath JAR from a URL twice: it approves the first copy and then loads the second. Anyone who can define a classpath entry can have a benign JAR approved and a different one executed, giving arbitrary code execution inside the Jenkins controller JVM. On a fleet whose CI controller holds registry push credentials, kubeconfigs and cluster tokens, controller RCE is the shortest path from a build job to the GPU cluster's control plane. Affects Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier.

Who can reach it

An authenticated Jenkins user with permission to define classpath entries for scripts or Pipelines, plus the ability to host the JAR URL the controller fetches.

What to do

Update the Script Security Plugin past 1415.v9a_f9b_3a_c253d per the Jenkins advisory and restart the controller; plugin upgrades on Jenkins are a controller restart, not a fleet-wide action. Until then, review who holds script-approval and classpath-definition rights. No agent or GPU node reboot is involved.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.