August 10, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-27099NVD

Vulnerability Summary

Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or Agent/Disconnect permission.
Severity Level
HIGH(8.0)
Published Date
Feb 18, 2026
Last Modified
Feb 20, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.05%Probability
Root Weakness (CWE)
The software does not neutralize user-controllable input before it is placed in output that is used as a web page.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh