SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84662

MEDIUM · CVSS 4.3 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Jenkins LDAP Plugin versions 807.809.vd3a_4e5e4ec98 and earlier are vulnerable due to improper handling of user-specified URLs through Stapler data binding, potentially allowing attackers to redirect connections to malicious endpoints. This vulnerability could lead to unauthorized access or data exposure, making it critical for organizations using Jenkins with this plugin to prioritize remediation. Users of affected Jenkins versions should assess their configurations and apply necessary updates to mitigate the risk.

CVE
CVE-2026-84662
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%
Jenkins

Original NVD Description

Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-specified URL.