CVE-2026-84662: Jenkins Project Jenkins LDAP Plugin

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-specified URL.

Affected products

  • Jenkins Project Jenkins LDAP Plugin: up to and including 807.809.vd3a_4e5e4ec98

Published 2026-09-02. Last modified 2026-09-03.