Executive brief
The Jenkins SAML Plugin allows authentication systems to verify user identities using centralized identity providers. A vulnerability in versions 4.618 and earlier permits attackers to overwrite the identity provider metadata file through web form manipulation, enabling them to impersonate any user and gain unauthorized access to Jenkins systems.
Technical details
The vulnerability exists in Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier due to insufficient type restrictions in Stapler data binding. When processing HTTP form submissions, the plugin fails to properly validate the types being instantiated, allowing attackers with network access to specify arbitrary configuration objects. By crafting a malicious form submission, an attacker can overwrite the SAML identity provider metadata file with attacker-controlled content. This enables the attacker to redirect authentication requests to a malicious identity provider or modify user assertions, resulting in authentication bypass and assumption of any user's identity including administrators.
Affected products
- Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier
Timeline
- 2026-09-02: disclosed: Published in Jenkins Security Advisory 2026-09-02