Skip to main content
Vulnerability Database/CVE-2026-92136

CVE-2026-92136: Jenkins OWASP Dependency-Check XSS Flaw

CVE-2026-92136 is a stored cross-site scripting vulnerability in Jenkins OWASP Dependency-Check Plugin that allows attackers with Item/Configure permission to inject malicious scripts. This post covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-92136 Overview

CVE-2026-92136 is a stored cross-site scripting (XSS) vulnerability in the Jenkins OWASP Dependency-Check Plugin version 5.6.4 and earlier. The plugin fails to escape Common Weakness Enumeration (CWE) values rendered from Dependency-Check reports on the Jenkins user interface. Attackers holding Item/Configure permission can inject malicious script content that executes in the browser of any Jenkins user viewing the report. The flaw is tracked as [CWE-79] and is documented in the Jenkins Security Advisory #SECURITY-3992.

Critical Impact

Authenticated attackers with configure-level permissions can execute arbitrary JavaScript in Jenkins sessions, enabling credential theft, session hijacking, and pipeline tampering.

Affected Products

  • Jenkins OWASP Dependency-Check Plugin 5.6.4
  • Jenkins OWASP Dependency-Check Plugin versions prior to 5.6.4
  • Jenkins controllers using the plugin to display Dependency-Check reports

Discovery Timeline

  • 2026-09-16 - CVE CVE-2026-92136 published to NVD
  • 2026-09-16 - Jenkins Security Advisory SECURITY-3992 released
  • 2026-09-16 - Last updated in NVD database

Technical Details for CVE-2026-92136

Vulnerability Analysis

The Jenkins OWASP Dependency-Check Plugin ingests Dependency-Check XML or JSON reports and renders findings inside the Jenkins UI. Each finding includes a CWE identifier and description sourced from the input report. The plugin writes these CWE values directly into HTML output without applying output encoding or escaping. An attacker who can influence the report contents can embed HTML or JavaScript in the CWE field, which the browser then parses and executes.

Because the payload is persisted with the build record, the injected script fires every time a Jenkins user opens the affected report. Execution occurs in the security context of the viewing user, including administrators. Successful exploitation allows the attacker to steal session cookies, invoke Jenkins REST APIs on behalf of the victim, modify job configurations, or pivot to secrets accessible through the credentials plugin.

Root Cause

The plugin performs improper neutralization of input during web page generation [CWE-79]. CWE fields extracted from Dependency-Check reports are treated as trusted display strings rather than untrusted data. No HTML entity encoding is applied before insertion into the DOM.

Attack Vector

Exploitation requires authenticated access with Item/Configure permission. The attacker crafts or modifies a Dependency-Check report so that a CWE value contains an HTML or script payload. When the report is processed by the plugin and rendered on the Jenkins UI, the payload executes in the victim's browser. User interaction is required, since a Jenkins user must load the report page for the stored payload to fire.

For technical specifics, refer to the Jenkins Security Advisory #SECURITY-3992. No public proof-of-concept exploit code has been published.

Detection Methods for CVE-2026-92136

Indicators of Compromise

  • Dependency-Check report artifacts containing HTML tags, <script> elements, or event handler attributes such as onerror= and onload= inside CWE fields
  • Unexpected outbound HTTP requests from Jenkins user browsers to attacker-controlled domains after viewing build reports
  • Anomalous Jenkins API calls originating from administrator sessions shortly after opening a Dependency-Check report

Detection Strategies

  • Scan stored Dependency-Check report files on the Jenkins controller for CWE values containing angle brackets or JavaScript keywords
  • Enable Content Security Policy (CSP) reporting in Jenkins and monitor violations tied to plugin-generated report pages
  • Correlate Item/Configure permission grants with subsequent Dependency-Check report uploads to identify suspicious workflow patterns

Monitoring Recommendations

  • Forward Jenkins audit logs, plugin activity, and web access logs to a centralized analytics platform for retention and correlation
  • Alert on job configuration changes that introduce new report file paths or external artifact sources for the Dependency-Check plugin
  • Track browser-side telemetry for unexpected script execution on Jenkins domains through endpoint or browser isolation tooling

How to Mitigate CVE-2026-92136

Immediate Actions Required

  • Upgrade the Jenkins OWASP Dependency-Check Plugin to a fixed release as identified in Jenkins Security Advisory #SECURITY-3992
  • Audit accounts holding Item/Configure permission and revoke access that is not operationally required
  • Review recent Dependency-Check report artifacts for embedded HTML or script payloads and remove affected builds

Patch Information

The Jenkins project addressed the stored XSS by escaping CWE values before rendering them in the UI. Administrators should install the patched Dependency-Check Plugin version referenced in the official advisory. Verify the installed version through the Jenkins Plugin Manager after upgrade.

Workarounds

  • Restrict Item/Configure permission to trusted administrators until the patched plugin version is deployed
  • Disable the Dependency-Check Plugin on affected controllers if immediate patching is not feasible
  • Enforce a strict Content Security Policy for Jenkins to limit inline script execution in report views

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.