CVE-2026-84672

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 16:17

Updated : 2026-09-03 17:13


NVD link : CVE-2026-84672

Mitre link : CVE-2026-84672

CVE.ORG link : CVE-2026-84672


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key