PT-2026-44016 · Jenkins · Jenkins Appspider Plugin

Surrealgrain

·

Published

2026-05-27

·

Updated

2026-05-27

·

CVE-2026-48923

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connect to an attacker-specified URL.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2026-48923

Affected Products

Jenkins Appspider Plugin