CVE-2026-84672: Microsoft Jenkins Microsoft Entra ID (previously Azure AD) Plugin vulnerability

Published Sep 2, 2026
·
Updated

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0bff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.

Affected Software

1 affected component
Microsoft Jenkins Microsoft Entra ID (previously Azure AD) Plugin<=710.v0b_ff8e9cc2d2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Jenkins Microsoft Entra ID (previously Azure AD) Plugin to a version that resolves this vulnerability.

    Fixed in 710.v0b_ff8e9cc2d2

Event History

Sep 2, 2026
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
Description

Frequently Asked Questions

1

Who is exposed to this issue?

Jenkins instances using the Microsoft Entra ID Plugin version 710.v0b_ff8e9cc2d2 or earlier are affected when permissions are configured for Entra groups. Exposure depends on an attacker being able to create an Entra group whose display name matches that of a privileged group.

2

What does an attacker need to exploit it?

The attacker needs the ability to create an Entra group with a display name that collides with a privileged group's display name. The plugin's use of group display names in addition to unique object IDs can then cause the attacker-created group to receive the configured privileged group's permissions.

3

How can administrators identify potentially affected permission assignments?

Review Jenkins permissions configured for Entra groups and identify privileged groups whose display names could be duplicated by groups an attacker is permitted to create. The affected behavior applies to plugin versions 710.v0b_ff8e9cc2d2 and earlier.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203