CVE-2026-57288

Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated attackers to inject LDAP wildcard characters to enumerate directory entries and to authenticate as a matching user whose password they know without knowing their exact user name.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:active_directory:*:*:*:*:*:jenkins:*:*

History

No history.

Information

Published : 2026-06-24 14:17

Updated : 2026-06-26 19:08


NVD link : CVE-2026-57288

Mitre link : CVE-2026-57288

CVE.ORG link : CVE-2026-57288


JSON object : View

Products Affected

jenkins

  • active_directory
CWE
CWE-90

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')