CVE-2026-57281 Details
Description
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates the script.
A vulnerability exists in the Jenkins Script Security Plugin in versions through 1402.v94c9ce464861, allowing for a sandbox bypass. The plugin fails to reject Groovy Abstract Syntax Tree (AST) transformation annotations that include an 'extensions' member. This oversight enables attackers who can execute sandboxed Groovy scripts to run code outside the sandbox, provided a suitable script is available on the classpath of the component evaluating the script.
Users of the Jenkins Script Security Plugin should update to version 1402.1405.vc96e74964250, which addresses this vulnerability by rejecting annotations with an 'extensions' member during sandbox compilation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:60239 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60246 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60247 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60248 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60249 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60250 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60251 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60252 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60254 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60256 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60259 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-57281 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2492200 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57281.json | redhat-SADP | |
| https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3793 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-693 | Protection Mechanism Failure | CISA-ADP |
| CWE-917 | Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') | redhat-SADP |
| CWE-93 | Improper Neutralization of CRLF Sequences ('CRLF Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| jenkins script security | <= 1402.v94c9ce464861 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 27, 2026 | CVE Modified | redhat-SADP |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 27, 2026 | Initial Analysis | [email protected] |
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |