LDAP Plugin for Jenkins Enables Unauthorized URL Connections
CVE-2026-84662

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
2 September 2026

What is CVE-2026-84662?

The LDAP Plugin for Jenkins contains a security vulnerability that allows attackers to connect to URLs specified by them through Stapler data binding. This flaw can lead to unauthorized access and potential exploitation of the system, enabling malicious actors to manipulate server operations and data.

Affected Version(s)

Jenkins LDAP Plugin 0 <= 807.809.vd3a_4e5e4ec98

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.