All verified exploits

CVE-2026-27099 Stored XSS in Offline Cause Description

Deterministic high Jenkins Added cve-verified-cve-2026-27099

Detects Jenkins instances running versions 2.483 through 2.550 (weekly) or 2.492.1 through 2.541.1 (LTS) where the 'Mark temporarily offline' feature renders the user-provided offline cause description as raw HTML without escaping. Attackers with Agent/Configure or Agent/Disconnect permissions can inject JavaScript that executes when administrators view the agent status page, enabling session hijacking and credential theft.

Is your app exploitable through CVE-2026-27099?

Scan your domain free