CVE-2026-84672
moderateEntra group display-name collision authorization bypass in Jenkins Microsoft Entra ID plugin
The Jenkins Microsoft Entra ID (previously Azure AD) plugin through version 710.v0b_ff8e9cc2d2 evaluates group-based permissions using both the group's unique object ID and its display name, a user-controlled identifier, resulting in an authorization bypass (CWE-639). An attacker who can create a group in the connected Microsoft Entra tenant can craft a group whose display name collides with that of a privileged group, causing the plugin to grant the attacker the permissions configured for that privileged group. Successful exploitation yields elevated access to the Jenkins controller with high confidentiality, integrity, and availability impact, reflected in the 8.8 (high) CVSS 3.1 score. Any Jenkins installation that uses the affected plugin and maps Jenkins permissions to Entra ID groups is affected. There is no known public proof-of-concept, the issue is not in CISA KEV, and the EPSS score of ~0.2% (14th percentile) suggests exploitation has not yet been widely observed.
What to do: Upgrade the Microsoft Entra ID plugin to a release newer than 710.v0b_ff8e9cc2d2 as soon as possible. As interim mitigations, restrict who can create groups in the Microsoft Entra tenant to trusted administrators and verify that no existing group's display name duplicates the display name of a privileged group used for Jenkins authorization. Administrators using Entra-group-based permissions should review those mappings after patching to confirm no unauthorized permissions were granted.
| Jenkins project (jenkinsci) Microsoft Entra ID (previously Azure AD) Plugin for Jenkins | 710.v0b_ff8e9cc2d2 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.
- Weakness
- CWE-639
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.