CVE-2026-92134 Overview
CVE-2026-92134 is a stored cross-site scripting (XSS) vulnerability in the Jenkins Warnings Plugin version 13.10258.va_17d49a_78c3b_ and earlier. The plugin fails to validate the analysis results identifier when a job configuration is submitted through the REST application programming interface (API). Attackers holding Item/Configure permission can supply a javascript: scheme URL as the identifier, which is later rendered in the Jenkins user interface. When another user visits the affected job page, the injected script executes in their browser session under the Jenkins origin.
Critical Impact
Authenticated attackers with Item/Configure permission can inject persistent JavaScript that executes in the context of higher-privileged Jenkins users, enabling session theft and administrative action abuse.
Affected Products
- Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier
- Jenkins controller instances with the Warnings Plugin installed
- Jenkins jobs configured through the REST API by users with Item/Configure permission
Discovery Timeline
- 2026-09-16 - CVE-2026-92134 published to the National Vulnerability Database (NVD)
- 2026-09-16 - Jenkins Security Advisory SECURITY-3937 published
- 2026-09-16 - Last updated in NVD database
Technical Details for CVE-2026-92134
Vulnerability Analysis
The Warnings Plugin exposes static analysis results per job, each addressed by an identifier that becomes part of a URL rendered in the Jenkins UI. When a job configuration is submitted through the REST API, the plugin accepts the identifier without validating its scheme or format. An attacker with Item/Configure permission supplies a javascript: URL as the identifier. Jenkins stores the value in the job configuration and later emits it into an anchor href attribute on the results page. When a victim clicks the link, the browser evaluates the JavaScript payload in the Jenkins origin.
Because the payload is persisted in job configuration XML, this is a stored XSS classified under [CWE-79]. Exploitation requires user interaction from a victim navigating to the affected job, matching the UI:R component in the CVSS vector.
Root Cause
The REST API code path skips the scheme allowlist enforced by the standard web UI form submission. The plugin trusts client-supplied identifiers and treats them as safe URL fragments. No filtering rejects javascript:, data:, or vbscript: schemes prior to storage or rendering.
Attack Vector
An attacker with Item/Configure permission on any job sends a crafted REST API request that sets the analysis results identifier to a javascript: URL containing an attacker-controlled payload. A Jenkins administrator or other authenticated user who later browses the job triggers script execution, allowing session cookie exfiltration, cross-site request forgery (CSRF) token theft, or arbitrary Jenkins administrative actions in the victim's context.
// No verified public proof-of-concept is available.
// Refer to Jenkins Security Advisory SECURITY-3937 for technical details.
Detection Methods for CVE-2026-92134
Indicators of Compromise
- Job config.xml files containing identifier fields with javascript:, data:, or vbscript: URL schemes
- REST API POST requests to job configuration endpoints originating from low-privileged accounts holding only Item/Configure
- Unexpected outbound HTTP requests from Jenkins user browsers to attacker-controlled domains shortly after loading a job page
Detection Strategies
- Scan Jenkins JENKINS_HOME/jobs/*/config.xml for Warnings Plugin identifier fields containing non-http(s) schemes
- Inspect Jenkins access logs for POST requests to /job/*/configSubmit or /job/*/config.xml from accounts without Overall/Administer
- Alert on browser console errors or content security policy (CSP) violations on Jenkins result pages
Monitoring Recommendations
- Forward Jenkins audit logs and reverse proxy access logs to a centralized analytics platform
- Track changes to job configuration XML through version control or file integrity monitoring
- Review Item/Configure permission grants and remove access from accounts that do not require it
How to Mitigate CVE-2026-92134
Immediate Actions Required
- Upgrade the Jenkins Warnings Plugin to a version later than 13.10258.va_17d49a_78c3b_ as published in the Jenkins Security Advisory
- Audit existing job configurations for identifier fields containing javascript: or other executable URL schemes and remove them
- Restrict Item/Configure permission to trusted users until patching is complete
Patch Information
Jenkins has released a fixed version of the Warnings Plugin. Refer to the Jenkins Security Advisory 2026-09-16 (SECURITY-3937) for the exact fixed version and download instructions. Update through the Jenkins Plugin Manager or by replacing the plugin .hpi file on the controller.
Workarounds
- Remove the Warnings Plugin from Jenkins controllers where static analysis reporting is not required
- Revoke Item/Configure permission from untrusted accounts through Matrix Authorization or Role-Based Strategy
- Enforce a strict Content Security Policy on the Jenkins reverse proxy to block inline script execution from javascript: URLs
# Example: list jobs whose config.xml contains javascript: identifiers
grep -rEl 'id>[^<]*javascript:' "$JENKINS_HOME/jobs/"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
