CVE-2026-84662: Jenkins Project Jenkins LDAP Plugin
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-specified URL.
Affected products
- Jenkins Project Jenkins LDAP Plugin: up to and including 807.809.vd3a_4e5e4ec98
Published 2026-09-02. Last modified 2026-09-03.