CVE-2026-92141
Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
- Published Sep 16, 2026
- CVSS 4.3 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)