Junglewise Threat Intelligence

CVE-2026-48923: Jenkins AppSpider Plugin missing permission check in form validation

CVE-2026-48923 · Severity: medium · CVSS 4.3 · Published 2026-05-27

Technologies: com.rapid7:jenkinsci-appspider-plugin (Maven). Vendors: Maven, Jenkins Project, Jenkins.

Executive brief

The Jenkins AppSpider Plugin, which integrates security scanning into the Jenkins automation server, contains a security flaw in its form validation logic. This vulnerability allows a user with basic read-only access to the Jenkins system to trigger network requests to arbitrary web addresses. This could be used by an attacker to probe internal network resources or interact with external systems that should be restricted.

Technical details

The AppSpider Plugin for Jenkins, up to and including version 1.0.17, lacks a proper permission check in a method implementing form validation. This vulnerability (CWE-269) allows an authenticated attacker with 'Overall/Read' permissions to perform Server-Side Request Forgery (SSRF) by specifying an arbitrary URL for the Jenkins controller to connect to. The root cause is the absence of an authorization check (such as Jenkins.ADMINISTER) on the validation endpoint. The issue is resolved in version 1.0.18, which now requires 'Overall/Administer' permission to access the affected method.

Affected products

  • Jenkins Project AppSpider Plugin <= 1.0.17

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory
  • 2026-05-27: patched: Fixed in version 1.0.18

References

Related threats