LDAP Referral Handling Vulnerability in Jenkins Active Directory Plugin
CVE-2026-48918

6.6MEDIUM

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
27 May 2026

What is CVE-2026-48918?

The Jenkins Active Directory Plugin versions 2.41 and earlier have a vulnerability that allows the plugin to follow LDAP referrals by default. This behavior can expose the system to various security risks, including information disclosure and unauthorized access, as it may inadvertently allow connections to untrusted LDAP servers. Administrators should review their configurations and consider updating to safer versions to mitigate this risk.

Affected Version(s)

Jenkins Active Directory Plugin 0 <= 2.41

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.