Permissions Escalation Vulnerability in Jenkins Microsoft Entra ID Plugin
CVE-2026-84672
8.8HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 2 September 2026
What is CVE-2026-84672?
The Jenkins Microsoft Entra ID Plugin exposes a permissions escalation vulnerability due to its method of granting group permissions. Specifically, the plugin relies on both the group's unique object ID and its display name to manage access rights. This creates a security risk; an attacker with the ability to create an Entra group can potentially exploit a collision in display names to inherit permissions assigned to a privileged group. This can lead to unauthorized access and control over sensitive resources within the Jenkins environment, highlighting the need for improved validation mechanisms in managing group affiliations.
Affected Version(s)
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 0 <= 710.v0b_ff8e9cc2d2