GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins LDAP plugin: Stapler data binding lets a low-privileged user make the controller connect to any URL

CVE-2026-84662Control plane, storage & DevOpscurated

Impact

The plugin accepts a connection URL through Stapler data binding, so a low-privileged user can make the Jenkins controller open a connection to a host of their choosing. The controller is usually one of the better-positioned machines on a fleet network - it reaches build agents, registries, the cluster API and management subnets that a tenant cannot touch directly - which is what makes a server-side request from it worth having. Practical use is internal reachability probing and pulling the controller into an attacker-controlled LDAP endpoint that can harvest whatever the connection presents. Jenkins scores it integrity-low, not a takeover. Affects LDAP plugin 807.809.vd3a_4e5e4ec98 and earlier.

Who can reach it

An authenticated Jenkins user with low privileges who can reach the form endpoint that binds the LDAP connection URL. No administrative rights required; the attacker does not need to already reach the target host, the controller does it for them.

What to do

Upgrade the LDAP plugin past 807.809.vd3a_4e5e4ec98 per SECURITY-3678 in the 2026-09-02 Jenkins advisory; the advisory does not name a fixed release number, so take the current plugin version. Cost is a controller restart to load the plugin - queue pauses, agents reconnect, running builds lost unless drained. No GPU node impact. Egress filtering from the controller limits how far an unpatched instance can be pointed, but does not close the flaw.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.