Open Redirect Vulnerability in Jenkins Keycloak Authentication Plugin
CVE-2026-92141
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-92141?
The Jenkins Keycloak Authentication Plugin prior to version 2.4.1 contains an open redirect vulnerability that does not validate the redirect URL after user authentication. This flaw can be exploited by malicious actors to redirect users to arbitrary URLs, potentially facilitating phishing attempts and compromising user credentials. Organizations utilizing this plugin should upgrade to the latest version to mitigate the risk.
Affected Version(s)
Jenkins Keycloak Authentication Plugin 0 <= 2.4.1