← All findings

Jenkins LDAP PluginCVE-2026-84662

Jenkins rejected the form. The connection had already happened.

A code-generation tool opened a network connection on behalf of a user without administrator permission.

01 · The result

An outgoing connection from a form

Jenkins helps development teams automate builds, tests and deployments. A Pipeline describes those jobs. The Snippet Generator is a small tool for writing one: fill out a form, and Jenkins returns a piece of code.

In the local test, submitting that form also made Jenkins contact a supplied server. The signed-in user did not have administrator permission. Jenkins rejected the form's result, but the connection had already reached the test server.

The connection came from the LDAP Plugin, which connects Jenkins to identity directories containing information such as users and groups. Generating a code snippet should not grant permission to initiate that directory connection.

The LDAP authorization flaw is now CVE-2026-84662 / SECURITY-3678. Jenkins fixed the plugin and publicly credits me, alongside independent reporters Samy Medjahed and Eliott Laurie.

02 · The ordering problem

The connection came before the check

Jenkins turns form settings into Java objects, structures that hold data and related behavior. This is called data binding. Creating an object runs its constructor: code that prepares it for use.

The LDAP configuration constructor did more than store settings. It contacted a directory server. This happened before Jenkins checked whether the object was a valid Pipeline step, and without checking whether the user had permission to make the connection.

Rejecting the object did not undo its side effect

Recorded vulnerable path

  1. 01Read the formCreate an object from its settings
  2. 02Contact the serverThe object opens a connection
  3. 03Return an errorThe object is not a valid Pipeline step

The final check concerns the object’s type. It does not establish that the user was allowed to initiate the earlier connection.

There are two separate questions here: is this the right kind of object? and is this user allowed to perform this operation? A late answer to the first question does not replace a permission check for the second.

This is a server-side request forgery, or SSRF: a user causes a server to make a connection it should not make on that user's behalf. Here, the connection came from the Jenkins server, called the controller, not from the user's browser.

03 · The evidence

A connection, not just an error message

An error message alone would not prove that Jenkins had contacted anything. The test therefore recorded both sides: Jenkins logged a directory lookup, and a small test server listening for connections received one from Jenkins.

Recorded at the test listener

Source
Jenkins container
Observation
Outgoing connection received
Data
14-byte LDAP BindRequest

From the original local test. Addresses omitted.

A BindRequest starts an LDAP session. Receiving it confirmed that Jenkins had spoken LDAP to the supplied server. This established an outgoing connection, not a successful login, access to directory records, credential theft or code execution. The test required a signed-in user and the LDAP plugin.

Tested versions and evidence

The final report lists Jenkins 2.541.1 LTS, Pipeline: Groovy 4255.vd9c37f80fd8a_ and LDAP Plugin 807.v7d7de30930cf. Stapler, Jenkins's web framework, handled the data binding.

The evidence comes from the original local tests. The correction below is explained from the published patch, not a new before-and-after test.

04 · The correction

Check permission before connecting

The upstream fix adds an administrator-permission check at the start of the LDAP configuration constructor:

Jenkins.get().checkPermission(Jenkins.ADMINISTER);

A caller without that permission is stopped before the constructor reaches its network operation. The guard sits with the operation that needs authorization, rather than depending on the caller eventually rejecting the object.

With the fix, for a non-administrator
  1. 01Read the formStart creating the object
  2. 02Permission checkedAdministrator access required
  3. 03Access deniedNo LDAP connection is made on this path

Flow shown by the published patch.

The September 2 advisory rates the issue Medium. LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier are affected; 825.v2fca_37dd5b_cb_ is the fixed release.

  1. Local investigation and recorded LDAP connection.

  2. Upstream fix committed.

  3. Jenkins publishes the advisory, fixed version and researcher credits.

Thank you to the Jenkins security team and plugin maintainers for the fix and public acknowledgment.

Public references