CVE-2026-84672: Jenkins Project Jenkins Microsoft Entra Id Previously Azure Ad Plugin

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.

Affected products

  • Jenkins Project Jenkins Microsoft Entra Id Previously Azure Ad Plugin: up to and including 710.v0b_ff8e9cc2d2

Published 2026-09-02. Last modified 2026-09-03.