PT-2026-44009 · Jenkins · Ldap Plugin

·

CVE-2026-48916

·

Published

2026-05-27

·

Updated

2026-05-27

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins LDAP Plugin versions prior to 809.vd3a 4e5e4ec98
Description The software follows LDAP referrals from the configured LDAP server. An attacker who controls the LDAP server or performs a machine-in-the-middle attack can forward these referrals to an RMI URL. This causes the Jenkins controller to deserialize attacker-controlled data, which can lead to Remote Code Execution (RCE) if deserialization gadgets are present on the classpath. Deserialization gadgets are specific classes available in the application's environment that can be abused during the process of converting data back into an object to execute unintended code.
Recommendations Update Jenkins LDAP Plugin to version 809.vd3a 4e5e4ec98 or later.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48916
GHSA-FMJP-MW89-C6H6

Affected Products

Ldap Plugin