CVE-2026-84672: Microsoft Jenkins Microsoft Entra ID (previously Azure AD) Plugin vulnerability
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0bff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jenkins Microsoft Entra ID (previously Azure AD) Pluginto a version that resolves this vulnerability.Fixed in 710.v0b_ff8e9cc2d2
Event History
Frequently Asked Questions
Who is exposed to this issue?
Jenkins instances using the Microsoft Entra ID Plugin version 710.v0b_ff8e9cc2d2 or earlier are affected when permissions are configured for Entra groups. Exposure depends on an attacker being able to create an Entra group whose display name matches that of a privileged group.
What does an attacker need to exploit it?
The attacker needs the ability to create an Entra group with a display name that collides with a privileged group's display name. The plugin's use of group display names in addition to unique object IDs can then cause the attacker-created group to receive the configured privileged group's permissions.
How can administrators identify potentially affected permission assignments?
Review Jenkins permissions configured for Entra groups and identify privileged groups whose display names could be duplicated by groups an attacker is permitted to create. The affected behavior applies to plugin versions 710.v0b_ff8e9cc2d2 and earlier.