Description
Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-specified URL.
Published: 2026-09-02
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Jenkins LDAP Plugin up to version 807.809 allows an attacker to supply a URL that the plugin will connect to through Stapler data binding. This enables the plugin to reach arbitrary network addresses, potentially exposing internal services or data to external actors. Although the disclosed impact is limited to outbound connections, the ability to reach internal network resources can facilitate further attacks such as data exfiltration or internal reconnaissance. The vulnerability is categorized as CWE‑601, reflecting the unsafe handling of external URLs.

Affected Systems

The affected component is the Jenkins LDAP Plugin distributed by the Jenkins Project. All releases of the plugin identified as 807.809.vd3a_4e5e4ec98 and earlier are vulnerable. No other products or versions are listed as impacted.

Risk and Exploitability

The CVSS base score of 4.3 indicates a moderate severity. An exploitation would require network access to the Jenkins server and the ability to submit configuration data to the plugin. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. Given the absence of a known public exploit and the moderate score, the threat is considered low to moderate, but monitoring for anomalous outbound traffic is advisable.

Generated by OpenCVE AI on September 3, 2026 at 11:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest Jenkins LDAP Plugin release (patch available above version 807.809).
  • If an immediate update is not feasible, remove or disable the LDAP Plugin from the Jenkins instance to eliminate the attack surface.
  • Configure network or host‑based controls to restrict the Jenkins process from initiating outbound connections to arbitrary destinations, thereby limiting potential SSRF exploitation.

Generated by OpenCVE AI on September 3, 2026 at 11:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Ldap Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Ldap Plugin

Wed, 02 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-specified URL.
References

Subscriptions

Jenkins Project Jenkins Ldap Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-02T17:07:12.381Z

Reserved: 2026-09-01T21:55:27.034Z

Link: CVE-2026-84662

cve-icon Vulnrichment

Updated: 2026-09-02T17:07:04.957Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T16:17:30.857

Modified: 2026-09-03T17:13:16.490

Link: CVE-2026-84662

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T11:15:03Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')