CVE-2026-57288 Details
Description
Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated attackers to inject LDAP wildcard characters to enumerate directory entries and to authenticate as a matching user whose password they know without knowing their exact user name.
A vulnerability exists in the Jenkins Active Directory Plugin in versions through 2.41.1, where the user name is not properly escaped before creating the LDAP search filter for Windows native (ADSI) authentication. This flaw allows unauthenticated attackers to inject LDAP wildcard characters to enumerate directory entries. Additionally, attackers can authenticate as a user whose password they know, without needing to know the exact user name.
Users of the Active Directory Plugin should update to version 2.41.2, which addresses the vulnerability by properly escaping the user name in the LDAP search filter for Windows native authentication.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3651 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-90 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| jenkins active directory | < 2.41.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | Initial Analysis | [email protected] |
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |