Description
Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.
Published: 2026-05-27
Score: 6.6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Jenkins LDAP Plugin, versions 807.v7d7de30930cf and earlier, implements LDAP referral following. When a query receives a referral response, the plugin automatically redirects the search to the referred server without user intervention. This behavior can be leveraged if an attacker controls an external LDAP server or can craft referrals to an internal resource, potentially exposing sensitive directory information or redirecting queries to malicious endpoints. The impact is consistent with a vulnerability that may lead to unauthorized disclosure of directory contents and could facilitate further attacks on the system’s authentication mechanisms.

Affected Systems

All installations of the Jenkins LDAP Plugin with versions 807.v7d7de30930cf or earlier from the Jenkins Project are affected. The plugin is commonly used in Jenkins environments that perform LDAP authentication. No newer version is known to mitigate the issue.

Risk and Exploitability

The CVSS score of 6.6 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation data. The likely attack vector involves an adversary manipulating LDAP referral responses, possibly via a compromised LDAP server or an internal domain controller. The vulnerability requires the plugin to be active and configured to follow referrals; it does not allow arbitrary code execution or privilege escalation by itself, but it can provide attackers an additional surface for reconnaissance or targeted data exposure within the LDAP namespace.

Generated by OpenCVE AI on May 27, 2026 at 19:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Jenkins LDAP Plugin to a version newer than 807.v7d7de30930cf that removes automatic referral following.
  • If a patch update is not immediately possible, disable LDAP referral following in the plugin’s configuration or restrict the plugin’s network access to trusted LDAP servers.
  • Implement network controls or LDAP server policies that block or restrict referral responses from untrusted sources.

Generated by OpenCVE AI on May 27, 2026 at 19:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 20:15:00 +0000

Type Values Removed Values Added
Title LDAP Referral Handling Vulnerability in Jenkins LDAP Plugin

Wed, 27 May 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 27 May 2026 15:15:00 +0000

Type Values Removed Values Added
Description Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-05-27T15:51:05.829Z

Reserved: 2026-05-26T14:50:46.812Z

Link: CVE-2026-48916

cve-icon Vulnrichment

Updated: 2026-05-27T15:50:38.037Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-27T15:16:31.233

Modified: 2026-05-27T19:54:54.150

Link: CVE-2026-48916

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T20:00:05Z

Weaknesses