CVE-2026-92141

Summary

Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

Affected Software

VendorProductVersion RangeStatus
Jenkins ProjectJenkins Keycloak Authentication Plugin0 <= 2.4.1affected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References