CVE-2026-48918: SSRF
Published May 27, 2026
·Updated
Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.
Affected Software
2 affected components
Jenkins Jenkins Active Directory Plugin<=2.41
Jenkins Active Directory Jenkins<=2.41
Event History
May 27, 2026
CVE Published
via MITRE·02:13 PM
Data Sourced
via MITRE·02:13 PM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48918?
CVE-2026-48918 has a medium severity rating of 6.6.
2
What does CVE-2026-48918 involve?
CVE-2026-48918 involves the Jenkins Active Directory Plugin's default behavior of following LDAP referrals.
3
How do I fix CVE-2026-48918?
To fix CVE-2026-48918, update the Jenkins Active Directory Plugin to version 2.42 or later.
4
What are the potential impacts of CVE-2026-48918?
CVE-2026-48918 could allow unauthorized read access to sensitive information through SSRF.
5
Is CVE-2026-48918 present in any other versions of the Jenkins Active Directory Plugin?
CVE-2026-48918 affects all versions of the Jenkins Active Directory Plugin up to and including 2.41.