Feed/CVE-2026-48916
CVE-2026-48916MEDIUMCVSS 6.6

Jenkins LDAP Plugin follows LDAP referrals

Published May 27, 2026·Updated Jul 1, 2026

NVD Description

Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals from the configured LDAP server. These can forward to an RMI URL that causes Jenkins to deserialize attacker-controlled data, resulting in Remote Code Execution (RCE) on the Jenkins controller if deserialization "gadgets" are available on the classpath. This allows attackers able to control the configured LDAP server, or able to perform a machine-in-the-middle attack, to execute code on the Jenkins controller. LDAP Plugin 807.809.vd3a_4e5e4ec98 no longer follows LDAP referrals.

Affected Packages (1)

org.jenkins-ci.plugins:ldapMAVEN
Fixed in = 807.v7d7de30930cf

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free