← Back to search

CVE-2026-92137

8.8 HIGH

Published 2026-09-16 · Updated 2026-09-18

AI risk analysis

Summary
The flaw allows attackers with Item/Configure permission to create or replace arbitrary files in the Jenkins controller's file system, leading to potential remote code execution.
Exploitability
Exploitation is relatively straightforward given the required permission, but the attack vector is limited to users with Item/Configure access.
Blast radius
If exploited, the impact could be severe, as it could lead to full control over the Jenkins controller, including remote code execution.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Jenkins Robot Framework Plugin 6.2.3 or later.
rceauth-bypasswebjenkins

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content, which can lead to remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-22

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.