CVE-2026-92135 Overview
CVE-2026-92135 is a stored cross-site scripting (XSS) vulnerability in the Jenkins Coverage Plugin. Versions 3.3358.v9487dde48783 and earlier fail to validate the coverage results ID when a job configuration is submitted through the REST API. Attackers with Item/Configure permission can supply a javascript: scheme URL as the identifier. The payload persists in the job configuration and executes in the browser of any user who interacts with the affected coverage link. The weakness is classified under CWE-79: Improper Neutralization of Input During Web Page Generation.
Critical Impact
Authenticated attackers can plant persistent JavaScript payloads in Jenkins job configurations, hijacking sessions of higher-privileged users who view the affected coverage results.
Affected Products
- Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier
- Jenkins controllers hosting the vulnerable Coverage Plugin
- CI/CD pipelines that expose the plugin's REST API to configured users
Discovery Timeline
- 2026-09-16 - Jenkins publishes Security Advisory SECURITY-4118
- 2026-09-16 - CVE-2026-92135 published to NVD
- 2026-09-16 - Last updated in NVD database
Technical Details for CVE-2026-92135
Vulnerability Analysis
The Coverage Plugin accepts a coverage results ID as part of a job configuration submitted through the Jenkins REST API. The plugin does not validate or sanitize the identifier value before rendering it as a URL in the Jenkins web interface. An attacker with Item/Configure permission on any job can substitute a javascript: scheme URL for the expected identifier. When another user clicks the resulting coverage link, the browser executes the attacker-controlled script in the context of the Jenkins origin.
The impact scales with the privilege of the victim. A Jenkins administrator viewing the malicious job triggers script execution under an authenticated administrator session. This enables session theft, CSRF against Jenkins management endpoints, plugin installation, or code execution on the controller through Groovy script consoles.
Root Cause
The root cause is missing input validation on a user-supplied identifier that is later emitted into HTML as a hyperlink target. The plugin trusts the REST API caller to submit a well-formed identifier and does not enforce an allow-list of URL schemes such as http and https. See the Jenkins Security Advisory 2026-09-16 for authoritative details.
Attack Vector
Exploitation requires network access to the Jenkins controller, authenticated access with Item/Configure permission, and user interaction from a victim who follows the poisoned coverage link. The attacker crafts a REST API request that sets the coverage results ID to a javascript: URL containing the payload. The payload is stored in job configuration and served to subsequent viewers of the coverage results page. No verified public proof-of-concept code is available at the time of publication.
Detection Methods for CVE-2026-92135
Indicators of Compromise
- Coverage results identifiers in job config.xml files containing javascript:, data:, or vbscript: URL schemes
- REST API POST requests to Jenkins job configuration endpoints originating from non-administrative accounts
- Unexpected changes to Coverage Plugin job configuration timestamps without a corresponding UI change event
Detection Strategies
- Audit Jenkins jobs/*/config.xml files for coverage identifiers that do not match expected alphanumeric patterns
- Review Jenkins access logs for POST requests to /job/*/configSubmit and REST API config.xml endpoints from accounts with only Item/Configure permission
- Correlate browser Content Security Policy violation reports from Jenkins with users viewing coverage results pages
Monitoring Recommendations
- Forward Jenkins controller access logs and audit logs to a centralized logging platform for pattern analysis
- Alert on modifications to Coverage Plugin configuration blocks that introduce non-HTTP URL schemes
- Track privilege usage of accounts holding Item/Configure but not Overall/Administer, which are the primary threat profile for this CVE
How to Mitigate CVE-2026-92135
Immediate Actions Required
- Upgrade the Jenkins Coverage Plugin to a version later than 3.3358.v9487dde48783 as published in the Jenkins Security Advisory
- Inventory jobs configured with the Coverage Plugin and audit stored coverage identifiers for suspicious URL schemes
- Restrict Item/Configure permission to trusted users pending patch deployment
Patch Information
Refer to the Jenkins Security Advisory 2026-09-16 (SECURITY-4118) for the fixed plugin version and upgrade instructions. Apply the update through the Jenkins Plugin Manager and restart the controller to activate the patched code.
Workarounds
- Remove or disable the Coverage Plugin on Jenkins controllers where an immediate upgrade is not possible
- Revoke Item/Configure permission from untrusted users and enforce role-based access control for job configuration
- Enable a strict Content Security Policy on the Jenkins controller to block inline and javascript: URL execution
# Verify installed Coverage Plugin version via Jenkins CLI
java -jar jenkins-cli.jar -s https://jenkins.example.com/ \
list-plugins | grep -i coverage
# Audit job configurations for suspicious coverage identifiers
grep -r -E 'javascript:|data:|vbscript:' \
$JENKINS_HOME/jobs/*/config.xml
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
