CVE-2026-42525

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:azure_ad:*:*:*:*:*:jenkins:*:*

History

No history.

Information

Published : 2026-04-29 14:16

Updated : 2026-06-17 10:47


NVD link : CVE-2026-42525

Mitre link : CVE-2026-42525

CVE.ORG link : CVE-2026-42525


JSON object : View

Products Affected

jenkins

  • azure_ad
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')