Database/Control plane, storage & DevOps
Jenkins LDAP plugin: Stapler data binding lets a low-privileged user make the controller connect to any URL
Impact
The plugin accepts a connection URL through Stapler data binding, so a low-privileged user can make the Jenkins controller open a connection to a host of their choosing. The controller is usually one of the better-positioned machines on a fleet network - it reaches build agents, registries, the cluster API and management subnets that a tenant cannot touch directly - which is what makes a server-side request from it worth having. Practical use is internal reachability probing and pulling the controller into an attacker-controlled LDAP endpoint that can harvest whatever the connection presents. Jenkins scores it integrity-low, not a takeover. Affects LDAP plugin 807.809.vd3a_4e5e4ec98 and earlier.
Who can reach it
An authenticated Jenkins user with low privileges who can reach the form endpoint that binds the LDAP connection URL. No administrative rights required; the attacker does not need to already reach the target host, the controller does it for them.
What to do
Upgrade the LDAP plugin past 807.809.vd3a_4e5e4ec98 per SECURITY-3678 in the 2026-09-02 Jenkins advisory; the advisory does not name a fixed release number, so take the current plugin version. Cost is a controller restart to load the plugin - queue pauses, agents reconnect, running builds lost unless drained. No GPU node impact. Egress filtering from the controller limits how far an unpatched instance can be pointed, but does not close the flaw.
References
Related entries
- Jenkins Parameterized Remote Trigger plugin: remote trigger tokens stored unencrypted in job config.xmlCVE-2026-84676 · Jenkins Parameterized Remote Trigger plugin (tokens stored unencrypted in job config.xml)Medium
- GitLab CE/EE: developer-role user can modify package registry metadata without maintainer rightsCVE-2026-8667 · GitLab CE/EE (package registry metadata authorization)Medium
- Infineon cryptographic library (ECDSA) in security microcontrollers: Electromagnetic side channel in Infineon's ECDSACVE-2024-45678 · Infineon cryptographic library (ECDSA) in security microcontrollersMedium
- Slurm (slurmdbd accounting, Coordinator role): A Coordinator - the delegated role a site gives a team lead over theirCVE-2025-43904 · Slurm (slurmdbd accounting, Coordinator role)Medium
- HTCondor (condor_schedd / Access Point): A user plants a specially crafted job that lies dormant, then runs as aCVE-2025-66433 · HTCondor (condor_schedd / Access Point)Medium
- Jenkins core: build CLI -s flag cancels other users' builds without the Item/Cancel permissionCVE-2026-84657 · Jenkins core (build CLI command, -s flag skips Item/Cancel check)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.