VYPR
Medium severity4.3NVD Advisory· Published May 27, 2026· Updated Jun 17, 2026

CVE-2026-48923

CVE-2026-48923

Description

Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connect to an attacker-specified URL.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.rapid7:jenkinsci-appspider-pluginMaven
< 1.0.181.0.18

Affected products

2
  • cpe:2.3:a:jenkins:appspider:*:*:*:*:*:jenkins:*:*+ 1 more
    • cpe:2.3:a:jenkins:appspider:*:*:*:*:*:jenkins:*:*range: <1.0.18
    • (no CPE)range: <=1.0.17

Patches

Vulnerability mechanics

References

3

News mentions

2