LDAP Referral Handling Vulnerability in Jenkins Active Directory Plugin
CVE-2026-48918
6.6MEDIUM
What is CVE-2026-48918?
The Jenkins Active Directory Plugin versions 2.41 and earlier have a vulnerability that allows the plugin to follow LDAP referrals by default. This behavior can expose the system to various security risks, including information disclosure and unauthorized access, as it may inadvertently allow connections to untrusted LDAP servers. Administrators should review their configurations and consider updating to safer versions to mitigate this risk.
Affected Version(s)
Jenkins Active Directory Plugin 0 <= 2.41