Detects Jenkins instances running versions 2.483 through 2.550 (weekly) or 2.492.1 through 2.541.1 (LTS) where the 'Mark temporarily offline' feature renders the user-provided offline cause description as raw HTML without escaping. Attackers with Agent/Configure or Agent/Disconnect permissions can inject JavaScript that executes when administrators view the agent status page, enabling session hijacking and credential theft.
Is your app exploitable through CVE-2026-27099?
Scan your domain free