216.73.216.36

CVE-2026-27099

· Published 18/02/2026 15:18 · Modified 18/02/2026 17:51

Labels: CVE-2026-27099 2026-02-18CVE-2026-27099CWE-79[email protected]

Essential information

Published
18/02/2026 15:18
Modified
18/02/2026 17:51
Author
Creator
CVSS
8.0 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or Agent/Disconnect permission.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
jenkins / jenkins cpe:2.3:a:jenkins:jenkins:2.483-2.550:*:*:*:*:*:*:*
jenkins / jenkins lts cpe:2.3:a:jenkins:jenkins_lts:2.492.1-2.541.1:*:*:*:*:*:*:*

References