Skip to main content
Vulnerability Database/CVE-2026-92135

CVE-2026-92135: Jenkins Coverage Plugin XSS Vulnerability

CVE-2026-92135 is a stored XSS vulnerability in Jenkins Coverage Plugin that allows attackers with Item/Configure permission to inject malicious JavaScript through coverage results ID. This post covers technical details, affected versions, impact, and mitigation strategies.

Published:

CVE-2026-92135 Overview

CVE-2026-92135 is a stored cross-site scripting (XSS) vulnerability in the Jenkins Coverage Plugin. Versions 3.3358.v9487dde48783 and earlier fail to validate the coverage results ID when a job configuration is submitted through the REST API. Attackers with Item/Configure permission can supply a javascript: scheme URL as the identifier. The payload persists in the job configuration and executes in the browser of any user who interacts with the affected coverage link. The weakness is classified under CWE-79: Improper Neutralization of Input During Web Page Generation.

Critical Impact

Authenticated attackers can plant persistent JavaScript payloads in Jenkins job configurations, hijacking sessions of higher-privileged users who view the affected coverage results.

Affected Products

  • Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier
  • Jenkins controllers hosting the vulnerable Coverage Plugin
  • CI/CD pipelines that expose the plugin's REST API to configured users

Discovery Timeline

  • 2026-09-16 - Jenkins publishes Security Advisory SECURITY-4118
  • 2026-09-16 - CVE-2026-92135 published to NVD
  • 2026-09-16 - Last updated in NVD database

Technical Details for CVE-2026-92135

Vulnerability Analysis

The Coverage Plugin accepts a coverage results ID as part of a job configuration submitted through the Jenkins REST API. The plugin does not validate or sanitize the identifier value before rendering it as a URL in the Jenkins web interface. An attacker with Item/Configure permission on any job can substitute a javascript: scheme URL for the expected identifier. When another user clicks the resulting coverage link, the browser executes the attacker-controlled script in the context of the Jenkins origin.

The impact scales with the privilege of the victim. A Jenkins administrator viewing the malicious job triggers script execution under an authenticated administrator session. This enables session theft, CSRF against Jenkins management endpoints, plugin installation, or code execution on the controller through Groovy script consoles.

Root Cause

The root cause is missing input validation on a user-supplied identifier that is later emitted into HTML as a hyperlink target. The plugin trusts the REST API caller to submit a well-formed identifier and does not enforce an allow-list of URL schemes such as http and https. See the Jenkins Security Advisory 2026-09-16 for authoritative details.

Attack Vector

Exploitation requires network access to the Jenkins controller, authenticated access with Item/Configure permission, and user interaction from a victim who follows the poisoned coverage link. The attacker crafts a REST API request that sets the coverage results ID to a javascript: URL containing the payload. The payload is stored in job configuration and served to subsequent viewers of the coverage results page. No verified public proof-of-concept code is available at the time of publication.

Detection Methods for CVE-2026-92135

Indicators of Compromise

  • Coverage results identifiers in job config.xml files containing javascript:, data:, or vbscript: URL schemes
  • REST API POST requests to Jenkins job configuration endpoints originating from non-administrative accounts
  • Unexpected changes to Coverage Plugin job configuration timestamps without a corresponding UI change event

Detection Strategies

  • Audit Jenkins jobs/*/config.xml files for coverage identifiers that do not match expected alphanumeric patterns
  • Review Jenkins access logs for POST requests to /job/*/configSubmit and REST API config.xml endpoints from accounts with only Item/Configure permission
  • Correlate browser Content Security Policy violation reports from Jenkins with users viewing coverage results pages

Monitoring Recommendations

  • Forward Jenkins controller access logs and audit logs to a centralized logging platform for pattern analysis
  • Alert on modifications to Coverage Plugin configuration blocks that introduce non-HTTP URL schemes
  • Track privilege usage of accounts holding Item/Configure but not Overall/Administer, which are the primary threat profile for this CVE

How to Mitigate CVE-2026-92135

Immediate Actions Required

  • Upgrade the Jenkins Coverage Plugin to a version later than 3.3358.v9487dde48783 as published in the Jenkins Security Advisory
  • Inventory jobs configured with the Coverage Plugin and audit stored coverage identifiers for suspicious URL schemes
  • Restrict Item/Configure permission to trusted users pending patch deployment

Patch Information

Refer to the Jenkins Security Advisory 2026-09-16 (SECURITY-4118) for the fixed plugin version and upgrade instructions. Apply the update through the Jenkins Plugin Manager and restart the controller to activate the patched code.

Workarounds

  • Remove or disable the Coverage Plugin on Jenkins controllers where an immediate upgrade is not possible
  • Revoke Item/Configure permission from untrusted users and enforce role-based access control for job configuration
  • Enable a strict Content Security Policy on the Jenkins controller to block inline and javascript: URL execution
bash
# Verify installed Coverage Plugin version via Jenkins CLI
java -jar jenkins-cli.jar -s https://jenkins.example.com/ \
  list-plugins | grep -i coverage

# Audit job configurations for suspicious coverage identifiers
grep -r -E 'javascript:|data:|vbscript:' \
  $JENKINS_HOME/jobs/*/config.xml

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.