CVE-2026-84672: Jenkins Project Jenkins Microsoft Entra Id Previously Azure Ad Plugin
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.
Affected products
- Jenkins Project Jenkins Microsoft Entra Id Previously Azure Ad Plugin: up to and including 710.v0b_ff8e9cc2d2
Published 2026-09-02. Last modified 2026-09-03.