jenkins-script-security-plugin: Jenkins Script Security Plugin: Sandbox bypass leading to arbitrary code execution
Published Jun 24, 2026
8.8
HIGHCVSS 3.1
EPSS 0.51%
Description
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection.
Affected products
-
- Version 0StatusaffectedConstraints<=1402.v94c9ce464861
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Jenkins Project | Jenkins Script Security Plugin | unaffected |
|
- ≤ 1402.v94c9ce464861
No data.
OpenShift Developer Tools and Services 4.12
ocp-tools-4/jenkins-rhel8:1786628667
Fixed · RHSA-2026:60247
OpenShift Developer Tools and Services 4.13
ocp-tools-4/jenkins-rhel8:1786628681
Fixed · RHSA-2026:60249
OpenShift Developer Tools and Services 4.14
ocp-tools-4/jenkins-rhel8:1786533561
Fixed · RHSA-2026:60248
OpenShift Developer Tools and Services 4.15
ocp-tools-4/jenkins-rhel8:1786533565
Fixed · RHSA-2026:60239
OpenShift Developer Tools and Services 4.16
ocp-tools-4/jenkins-rhel9:1787125166
Fixed · RHSA-2026:60251
OpenShift Developer Tools and Services 4.17
ocp-tools-4/jenkins-rhel9:1787124635
Fixed · RHSA-2026:60246
OpenShift Developer Tools and Services 4.18
ocp-tools-4/jenkins-rhel9:1787125069
Fixed · RHSA-2026:60250
OpenShift Developer Tools and Services 4.19
ocp-tools-4/jenkins-rhel9:1787124632
Fixed · RHSA-2026:60252
OpenShift Developer Tools and Services 4.20
ocp-tools-4/jenkins-rhel9:1787124925
Fixed · RHSA-2026:60259
OpenShift Developer Tools and Services 4.21
ocp-tools-4/jenkins-rhel9:1787125311
Fixed · RHSA-2026:60254
OpenShift Developer Tools and Services 4.22
ocp-tools-4/jenkins-rhel9:1787124779
Fixed · RHSA-2026:60256
OpenShift Developer Tools and Services
jenkins
Affected
OpenShift Developer Tools and Services
jenkins-2-plugins
Affected
OpenShift Developer Tools and Services
ocp-tools-4/jenkins-agent-base-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Developer Tools and Services 4.12 | ocp-tools-4/jenkins-rhel8:1786628667 | Fixed | RHSA-2026:60247 |
| OpenShift Developer Tools and Services 4.13 | ocp-tools-4/jenkins-rhel8:1786628681 | Fixed | RHSA-2026:60249 |
| OpenShift Developer Tools and Services 4.14 | ocp-tools-4/jenkins-rhel8:1786533561 | Fixed | RHSA-2026:60248 |
| OpenShift Developer Tools and Services 4.15 | ocp-tools-4/jenkins-rhel8:1786533565 | Fixed | RHSA-2026:60239 |
| OpenShift Developer Tools and Services 4.16 | ocp-tools-4/jenkins-rhel9:1787125166 | Fixed | RHSA-2026:60251 |
| OpenShift Developer Tools and Services 4.17 | ocp-tools-4/jenkins-rhel9:1787124635 | Fixed | RHSA-2026:60246 |
| OpenShift Developer Tools and Services 4.18 | ocp-tools-4/jenkins-rhel9:1787125069 | Fixed | RHSA-2026:60250 |
| OpenShift Developer Tools and Services 4.19 | ocp-tools-4/jenkins-rhel9:1787124632 | Fixed | RHSA-2026:60252 |
| OpenShift Developer Tools and Services 4.20 | ocp-tools-4/jenkins-rhel9:1787124925 | Fixed | RHSA-2026:60259 |
| OpenShift Developer Tools and Services 4.21 | ocp-tools-4/jenkins-rhel9:1787125311 | Fixed | RHSA-2026:60254 |
| OpenShift Developer Tools and Services 4.22 | ocp-tools-4/jenkins-rhel9:1787124779 | Fixed | RHSA-2026:60256 |
| OpenShift Developer Tools and Services | jenkins | Affected | n/a |
| OpenShift Developer Tools and Services | jenkins-2-plugins | Affected | n/a |
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-agent-base-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat rates this as an Important vulnerability in the Jenkins Script Security Plugin. Attackers with the ability to provide sandboxed Groovy scripts can bypass sandbox protections due to improper handling of implicit type casts in typed for-each loops, allowing arbitrary constructor invocation and potential code execution within the Jenkins JVM. The scope is unchanged (S:U) because the sandbox and the Jenkins controller share the same security authority — a sandbox escape executes code in the same context rather than crossing a trust boundary to a separate system.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jun 24, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jun–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.51% (0.00513) | 41.55th | v5 (v2026.06.15) |
| Jun 25, 2026 | 0.37% (0.00367) | 28.51th | v5 (v2026.06.15) |
References (8)
- https://access.redhat.com/security/cve/CVE-2026-57280 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2492199 Issue Tracking
- https://github.com/advisories/GHSA-c3jm-9vj7-5v66 Advisory
- https://github.com/jenkinsci/script-security-plugin/commit/858015c25c7bc7ab59c666307093b0e16b90048c
- https://github.com/jenkinsci/script-security-plugin/releases/tag/1402.1405.vc96e74964250
- https://nvd.nist.gov/vuln/detail/CVE-2026-57280
- https://www.cve.org/CVERecord?id=CVE-2026-57280
- https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3792 vendor-advisoryVendor Advisory
Change history (0)
No recorded changes yet.