ZeroHour

CVE-2026-84672

moderate

Entra group display-name collision authorization bypass in Jenkins Microsoft Entra ID plugin

CVSS 3.1
8.8 high
EPSS
<1%p14
Published
()
Modified
AI analysis

The Jenkins Microsoft Entra ID (previously Azure AD) plugin through version 710.v0b_ff8e9cc2d2 evaluates group-based permissions using both the group's unique object ID and its display name, a user-controlled identifier, resulting in an authorization bypass (CWE-639). An attacker who can create a group in the connected Microsoft Entra tenant can craft a group whose display name collides with that of a privileged group, causing the plugin to grant the attacker the permissions configured for that privileged group. Successful exploitation yields elevated access to the Jenkins controller with high confidentiality, integrity, and availability impact, reflected in the 8.8 (high) CVSS 3.1 score. Any Jenkins installation that uses the affected plugin and maps Jenkins permissions to Entra ID groups is affected. There is no known public proof-of-concept, the issue is not in CISA KEV, and the EPSS score of ~0.2% (14th percentile) suggests exploitation has not yet been widely observed.

What to do: Upgrade the Microsoft Entra ID plugin to a release newer than 710.v0b_ff8e9cc2d2 as soon as possible. As interim mitigations, restrict who can create groups in the Microsoft Entra tenant to trusted administrators and verify that no existing group's display name duplicates the display name of a privileged group used for Jenkins authorization. Administrators using Entra-group-based permissions should review those mappings after patching to confirm no unauthorized permissions were granted.

Affected
Jenkins project (jenkinsci) Microsoft Entra ID (previously Azure AD) Plugin for Jenkins710.v0b_ff8e9cc2d2 and earlier
Estimated exposure
moderate≈ a few thousand Jenkins controllers (roughly 1k–10k installations of this SSO plugin) — The Entra ID/Azure AD connector is a niche enterprise SSO plugin in the Jenkins ecosystem, where Jenkins publishes per-plugin active-install counts that place plugins of this type in the low thousands of controllers rather than the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.

Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.