cbcvebase.
CVE-2026-48923
published 2026-05-27

CVE-2026-48923: Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read…

medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connect to an attacker-specified URL.

Affected

24 ranges
VendorProductVersion rangeFixed in
jenkinsactive_directory
jenkinsactive_directory_plugin
jenkinsappspider< 1.0.181.0.18
jenkinsappspider
jenkinsappspider_plugin
jenkinsbitbucket_oauth
jenkinsbitbucket_oauth_plugin
jenkinscredentials_binding
jenkinscredentials_binding_plugin
jenkinsemail_extension
jenkinsemail_extension_plugin
jenkinsgithub_integration
jenkinsgithub_integration_plugin
jenkinsgroovy_libraries
jenkinsgroovy_libraries_plugin
jenkinsjob_import
jenkinsjob_import_plugin
jenkinsldap
jenkinsldap_plugin
jenkinsldap_referrals_in_active_directory
jenkinsldap_referrals_in_active_directory_plugin
jenkinsmultijob
jenkinsmultijob_plugin
jenkins_projectjenkins_appspider_plugin<= 1.0.17