Open Redirect Vulnerability in Jenkins Keycloak Authentication Plugin
CVE-2026-92141

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92141?

The Jenkins Keycloak Authentication Plugin prior to version 2.4.1 contains an open redirect vulnerability that does not validate the redirect URL after user authentication. This flaw can be exploited by malicious actors to redirect users to arbitrary URLs, potentially facilitating phishing attempts and compromising user credentials. Organizations utilizing this plugin should upgrade to the latest version to mitigate the risk.

Affected Version(s)

Jenkins Keycloak Authentication Plugin 0 <= 2.4.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.