Description
Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
Published: 2026-09-16
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Phishing via Open Redirect
Action: Apply Patch
AI Analysis

Impact

The Jenkins Keycloak Authentication Plugin version 2.4.1 and earlier allows an attacker to insert an arbitrary redirect URL after a user logs in, creating an open‑redirect flaw (CWE-601). This enables attackers to lure users to malicious sites that mimic legitimate login pages, facilitating credential harvesting and other phishing attacks. The vulnerability does not grant direct code execution or password exposure on its own, but it can be combined with social engineering to compromise account security.

Affected Systems

All Jenkins installations that use the Keycloak Authentication Plugin 2.4.1 or older are affected. The plugin is distributed by the Jenkins Project and is commonly used to integrate Keycloak as an authentication provider in Jenkins instances.

Risk and Exploitability

The CVSS score of 4.3 indicates a low to moderate severity, and the EPSS score of less than 1% shows a very low probability of exploitation at the time of assessment. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote via the web interface, where an attacker can supply a crafted login URL to redirect the user to a malicious site.

Generated by OpenCVE AI on September 18, 2026 at 04:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Jenkins Keycloak Authentication Plugin to the latest version that limits or validates redirect URLs.
  • Configure the plugin to only allow redirects to trusted domains or disable the redirect feature if it is not required.
  • Review all authentication flows for additional open‑redirect points and enforce strict URL validation to prevent phishing.

Generated by OpenCVE AI on September 18, 2026 at 04:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title Open Redirect in Jenkins Keycloak Authentication Plugin Enables Phishing

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Keycloak Authentication Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Keycloak Authentication Plugin

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
References

Subscriptions

Jenkins Project Jenkins Keycloak Authentication Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-16T18:33:08.864Z

Reserved: 2026-09-15T16:29:44.795Z

Link: CVE-2026-92141

cve-icon Vulnrichment

Updated: 2026-09-16T18:33:04.231Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:16.057

Modified: 2026-09-18T13:46:13.937

Link: CVE-2026-92141

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:00:04Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')