Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.jenkins-ci.plugins/ldap
  4. ›
  5. CVE-2026-48916

CVE-2026-48916: Jenkins LDAP Plugin follows LDAP referrals

May 27, 2026 (updated July 1, 2026)

Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals from the configured LDAP server. These can forward to an RMI URL that causes Jenkins to deserialize attacker-controlled data, resulting in Remote Code Execution (RCE) on the Jenkins controller if deserialization “gadgets” are available on the classpath.

This allows attackers able to control the configured LDAP server, or able to perform a machine-in-the-middle attack, to execute code on the Jenkins controller.

LDAP Plugin 807.809.vd3a_4e5e4ec98 no longer follows LDAP referrals.

References

  • github.com/advisories/GHSA-fmjp-mw89-c6h6
  • nvd.nist.gov/vuln/detail/CVE-2026-48916
  • www.jenkins.io/security/advisory/2026-05-27/

Code Behaviors & Features

Detect and mitigate CVE-2026-48916 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 807.809.0

Fixed versions

  • 807.809.0

Solution

Upgrade to version 807.809.0 or above.

Impact 6.6 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-918: Server-Side Request Forgery (SSRF)

Source file

maven/org.jenkins-ci.plugins/ldap/CVE-2026-48916.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Fri, 10 Jul 2026 12:16:56 +0000.