CVE-2026-27099 PUBLISHED

Assigner: jenkins
Reserved: 17.02.2026 Published: 18.02.2026 Updated: 18.02.2026

Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or Agent/Disconnect permission.

Product Status

Vendor Jenkins Project
Product Jenkins
Versions Default: affected
  • unaffected from 0 to 2.483 (excl.)
  • unaffected from 2.551 to * (excl.)
  • unaffected from 2.541.2 to 2.541.* (excl.)

References