Code Injection in Script Security - CVE-2026-92125
Published: September 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient implementation of security measures when the affected plugin does not reject the @GroovyASTTransformationClass annotation. A remote user can bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.