CVE-2026-48923: Medium severity Jenkins AppSpider Plugin vulnerability
Published May 27, 2026
·Updated
Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connect to an attacker-specified URL.
Affected Software
2 affected components
Jenkins AppSpider Plugin<=1.0.17
Jenkins Appspider Jenkins<1.0.18
Event History
May 27, 2026
CVE Published
via MITRE·02:13 PM
Data Sourced
via MITRE·02:13 PM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48923?
The severity of CVE-2026-48923 is medium with a CVSS score of 4.3.
2
How do I fix CVE-2026-48923?
To fix CVE-2026-48923, upgrade to Jenkins AppSpider Plugin version 1.0.18 or later.
3
What type of attack is associated with CVE-2026-48923?
CVE-2026-48923 allows attackers with Overall/Read permission to connect to an attacker-specified URL due to a lack of permission checks.
4
Which software is affected by CVE-2026-48923?
The affected software is Jenkins AppSpider Plugin version 1.0.17 and earlier.
5
What is the potential impact of CVE-2026-48923?
The potential impact of CVE-2026-48923 is the exposure of sensitive information through unauthorized URL connections.