Vulnerability record · CVE-2016-9299 · published 12 January 2017
CVE-2016-9299: Jenkins remoting Java deserialization RCE via LDAP lookup
Jenkins · Jenkins
The Jenkins remoting module before 2.32 and LTS before 2.19.3 deserializes untrusted Java objects, allowing a crafted serialized object to trigger an LDAP query to an attacker-controlled server. This is a remote, unauthenticated code execution flaw in a core component of a widely deployed CI server, so it matters for any internet- or network-exposed Jenkins instance.
Description
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution in a core Jenkins component with a public exploit and near-maximum EPSS probability.
What it is
The Jenkins remoting module before 2.32 and LTS before 2.19.3 deserializes untrusted Java objects, allowing a crafted serialized object to trigger an LDAP query to an attacker-controlled server. This is a remote, unauthenticated code execution flaw in a core component of a widely deployed CI server, so it matters for any internet- or network-exposed Jenkins instance.
Impact
An attacker gains arbitrary code execution in the context of the Jenkins process, which typically means full control of the CI server, its credentials, build jobs and connected agents.
Attack surface
Reachable over the network through the remoting channel; the CVSS vector shows AV:N/PR:N/UI:N, so no authentication or user interaction is required. The description does not specify which port or endpoint beyond the remoting module.
Exploitation
Not listed in CISA KEV, but EPSS is 0.96943 (99.887th percentile) and a public Exploit-DB entry (44642) exists, indicating mature, widely available exploitation.
What to do
- Upgrade Jenkins to 2.32 or later, or LTS 2.19.3 or later, and update the Fedora package if applicable.
- Restrict network access to Jenkins remoting and agent ports; do not expose them to untrusted networks.
- Enable the Jenkins security sandbox and avoid running builds with untrusted users or code.
- Monitor and restrict outbound LDAP traffic from Jenkins hosts to prevent the callback used by the exploit.
- Rotate credentials and secrets stored in Jenkins if compromise is suspected.
Detection
- Alert on outbound LDAP connections from Jenkins hosts to unexpected or external destinations.
- Monitor Jenkins logs for deserialization errors, remoting channel exceptions or unexpected class loading.
- Hunt for suspicious child processes spawned by the Jenkins Java process (e.g. shells, curl, wget).
- Review network flows for connections to attacker-controlled LDAP or HTTP callback infrastructure.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-9299 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-9299), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.