Executive brief
The Jenkins Active Directory Plugin is used to allow users to log into Jenkins using their corporate Windows credentials. A security flaw in this plugin allows attackers to use special characters to search the directory and log in as users without knowing their full usernames, provided they have the correct password. This could lead to unauthorized access to the Jenkins automation server and potential exposure of sensitive build data.
Technical details
The vulnerability exists in the Windows native (ADSI) authentication path of the Jenkins Active Directory Plugin. Due to a failure to sanitize or escape the username field before it is incorporated into an LDAP search filter, the component is susceptible to LDAP injection. An unauthenticated attacker can use LDAP wildcard characters (e.g., '*') to enumerate directory entries. Furthermore, an attacker who possesses a valid password for a user account can successfully authenticate without knowing the exact username by using wildcards to match the target entry. This issue affects versions 2.41.1 and earlier.
Affected products
- Jenkins Project Active Directory Plugin 2.41.1 and earlier
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory