CVE-2026-92141: Jenkins Keycloak Authentication Plugin vulnerability
Published Sep 16, 2026
·Updated
Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
Affected Software
1 affected component
Jenkins Keycloak Authentication Plugin<=2.4.1
Event History
Sep 16, 2026
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description
Frequently Asked Questions
1
Which installations are affected?
Jenkins installations using Keycloak Authentication Plugin version 2.4.1 or earlier are affected.
2
What does an attacker need to exploit this issue?
The issue allows an attacker to use an unrestricted post-login redirect URL to conduct phishing attacks. The available information does not state any additional access or authentication requirements.