PatchSiren cyber security CVE debrief
CVE-2026-48916 Jenkins Project CVE debrief
The Jenkins LDAP Plugin versions 807.v7d7de30930cf and earlier follow LDAP referrals, which can lead to Server-Side Request Forgery (SSRF) conditions. When the plugin processes LDAP referrals, it may make outbound connections to attacker-controlled servers specified in malicious referral responses. This behavior is classified under CWE-918 (Server-Side Request Forgery). The vulnerability requires high attack complexity and high privileges to exploit, with network-based attack vector. Successful exploitation could result in high impact to confidentiality, integrity, and availability. The Jenkins security team disclosed this issue on May 27, 2026 as part of their regular security advisory cycle.
- Vendor
- Jenkins Project
- Product
- Jenkins LDAP Plugin
- CVSS
- MEDIUM 6.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-06-02
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-06-02
Who should care
Organizations running Jenkins with LDAP authentication enabled, particularly those using LDAP plugin version 807.v7d7de30930cf or earlier. Security teams managing CI/CD infrastructure and identity federation architectures should prioritize review of LDAP referral configurations.
Technical summary
The Jenkins LDAP Plugin's handling of LDAP referrals creates an SSRF vulnerability. LDAP referrals are responses from an LDAP server directing the client to contact a different server for requested information. When the plugin automatically follows these referrals, it may connect to arbitrary attacker-specified hosts, potentially exposing internal services or enabling further attacks. The vulnerability requires high privileges and complex attack conditions, limiting practical exploitability but maintaining significant risk in multi-tenant or compromised-LDAP-server scenarios.
Defensive priority
medium
Recommended defensive actions
- Upgrade Jenkins LDAP Plugin to a version newer than 807.v7d7de30930cf when available per Jenkins security advisory
- Review LDAP server configurations and restrict referral handling where possible
- Monitor Jenkins instance network egress for unexpected outbound connections to non-LDAP infrastructure
- Audit Jenkins authentication logs for anomalous LDAP referral patterns
- Apply network segmentation controls to limit Jenkins controller egress to trusted LDAP endpoints only
Evidence notes
Official Jenkins security advisory confirms LDAP referral following behavior in affected plugin versions. CVSS 3.1 vector AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H supports medium severity classification. CWE-918 (SSRF) weakness designation aligns with LDAP referral handling vulnerability pattern.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48916 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48916
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48916 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48916
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.jenkins.io/security/advisory/2026-05-27/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.