CVE-2026-84662

Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-specified URL.

  • Published Sep 2, 2026
  • CVSS 4.3 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-84662 at the National Vulnerability Database