Junglewise Threat Intelligence

CVE-2026-48916: Jenkins LDAP Plugin Remote Code Execution via LDAP Referrals

CVE-2026-48916 · Severity: medium · CVSS 6.6 · Published 2026-05-27

Technologies: org.jenkins-ci.plugins:ldap (Maven). Vendors: Jenkins Project, Maven.

Executive brief

The Jenkins LDAP Plugin, which allows Jenkins to use LDAP directories for user authentication, is vulnerable to a remote code execution flaw. If an attacker can control the LDAP server or intercept network traffic between Jenkins and the server, they can redirect Jenkins to a malicious source. This allows the attacker to run unauthorized code on the Jenkins controller, potentially leading to a full system takeover and access to sensitive build data.

Technical details

The Jenkins LDAP Plugin (versions 807.v7d7de30930cf and earlier) fails to validate LDAP referrals. An attacker who controls the configured LDAP server or can perform a Machine-in-the-Middle (MitM) attack can provide a referral pointing to a malicious RMI URL. When Jenkins follows this referral, it attempts to deserialize attacker-controlled data. If suitable 'gadget' classes are present on the classpath, this results in Remote Code Execution (RCE) on the Jenkins controller. The vulnerability is tracked as a combination of SSRF (CWE-918) and unsafe deserialization. It has been patched in version 807.809.vd3a_4e5e4ec98 by disabling the following of LDAP referrals.

Affected products

  • Jenkins Project LDAP Plugin <= 807.v7d7de30930cf

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory
  • 2026-05-27: patched

References

Related threats