Permissions Escalation Vulnerability in Jenkins Microsoft Entra ID Plugin
CVE-2026-84672

8.8HIGH

What is CVE-2026-84672?

The Jenkins Microsoft Entra ID Plugin exposes a permissions escalation vulnerability due to its method of granting group permissions. Specifically, the plugin relies on both the group's unique object ID and its display name to manage access rights. This creates a security risk; an attacker with the ability to create an Entra group can potentially exploit a collision in display names to inherit permissions assigned to a privileged group. This can lead to unauthorized access and control over sensitive resources within the Jenkins environment, highlighting the need for improved validation mechanisms in managing group affiliations.

Affected Version(s)

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 0 <= 710.v0b_ff8e9cc2d2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.