CVE-2026-92136 PUBLISHED

Assigner: jenkins
Reserved: 15.09.2026 Published: 16.09.2026 Updated: 16.09.2026

Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

Product Status

Vendor Jenkins Project
Product Jenkins OWASP Dependency-Check Plugin
Versions Default: unaffected
  • affected from 0 to 5.6.4 (incl.)

References