Deserialization Vulnerability in Jenkins Active Directory Plugin by Jenkins
CVE-2026-48919
6.6MEDIUM
What is CVE-2026-48919?
The Active Directory Plugin for Jenkins, specifically versions 2.41 and earlier, contains a flaw that allows data from LDAP referrals to be deserialized without proper validation. This presents a potential risk where attackers might exploit this vulnerability to manipulate session information or execute unauthorized commands, thereby impacting the integrity and confidentiality of the Jenkins environment.
Affected Version(s)
Jenkins Active Directory Plugin 0 <= 2.41