{"id":"GHSA-85h6-5m3v-gx37","summary":"Jenkins has a stored XSS vulnerability in node offline cause description","details":"Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the \"Mark temporarily offline\" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or Agent/Disconnect permission.","aliases":["BIT-jenkins-2026-27099","CVE-2026-27099"],"modified":"2026-09-10T03:50:34.505671332Z","published":"2026-02-18T15:31:27Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-02-19T20:26:28Z","nvd_published_at":"2026-02-18T15:18:43Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27099"},{"type":"WEB","url":"https://github.com/jenkinsci/jenkins/commit/578c028e2cdfdc9e124d0ca389a80bb2bd231ab2"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/jenkins"},{"type":"WEB","url":"https://github.com/jenkinsci/jenkins/releases/tag/jenkins-2.541.2"},{"type":"WEB","url":"https://github.com/jenkinsci/jenkins/releases/tag/jenkins-2.551"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2026-02-18/#SECURITY-3669"}],"affected":[{"package":{"name":"org.jenkins-ci.main:jenkins-core","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.main/jenkins-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.542"},{"fixed":"2.551"}]}],"versions":["2.542","2.543","2.544","2.545","2.546","2.547","2.548","2.549","2.550"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-85h6-5m3v-gx37/GHSA-85h6-5m3v-gx37.json"}},{"package":{"name":"org.jenkins-ci.main:jenkins-core","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.main/jenkins-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.483"},{"fixed":"2.541.2"}]}],"versions":["2.483","2.484","2.485","2.486","2.487","2.488","2.489","2.490","2.491","2.492","2.492.1","2.492.2","2.492.3","2.493","2.494","2.495","2.496","2.497","2.498","2.499","2.500","2.501","2.502","2.503","2.504","2.504.1","2.504.2","2.504.3","2.505","2.506","2.507","2.508","2.509","2.510","2.511","2.512","2.513","2.514","2.515","2.516","2.516.1","2.516.2","2.516.3","2.517","2.518","2.519","2.520","2.521","2.522","2.523","2.524","2.525","2.526","2.527","2.528","2.528.1","2.528.2","2.528.3","2.529","2.530","2.531","2.532","2.533","2.534","2.535","2.536","2.537","2.538","2.539","2.540","2.541","2.541.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-85h6-5m3v-gx37/GHSA-85h6-5m3v-gx37.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}