Deserialization Vulnerability in Jenkins LDAP Plugin by Jenkins
CVE-2026-48917

6.6MEDIUM

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
27 May 2026

What is CVE-2026-48917?

The Jenkins LDAP Plugin versions up to and including 807.v7d7de30930cf are affected by a vulnerability that allows unvalidated deserialization of data from LDAP referrals. This flaw may enable an attacker to exploit the plugin, compromising the integrity and security of the Jenkins server and its associated configurations. It is recommended to upgrade to the latest version to mitigate any associated risks.

Affected Version(s)

Jenkins LDAP Plugin 0 <= 807.v7d7de30930cf

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.