Description
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.
Published: 2026-09-02
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Jenkins Microsoft Entra ID plugin, version 710.v0b_ff8e9cc2d2 and earlier, assigns group permissions using both a group's unique object ID and its display name. An attacker who can create a new Entra group whose display name collides with that of a privileged group will be granted the permissions associated with the privileged group. This flaw enables an attacker to obtain elevated rights within the Jenkins instance without needing the original group's object ID.

Affected Systems

All Jenkins installations that deploy the Microsoft Entra ID (Azure AD) plugin at or before the affected version are impacted. The vulnerability exists wherever the plugin is used to map Entra group permissions, regardless of the Jenkins version itself.

Risk and Exploitability

The CVSS score of 8.8 signals a high severity vulnerability. Although the EPSS score is not available and the issue is not listed in the CISA KEV catalog, the nature of the flaw – granting privileged permissions through a name collision – indicates a potentially high impact if exploited. Likely attack conditions include an attacker having permission to create Entra groups and access the Jenkins plugin endpoint. While no active exploits are documented, the high CVSS suggests that the risk remains significant until a patch is applied.

Generated by OpenCVE AI on September 3, 2026 at 11:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Jenkins Microsoft Entra ID plugin to the latest version that corrects the group permission mapping logic.
  • If an upgrade cannot occur immediately, restrict the ability to create new Entra groups to trusted administrators or enforce unique display names to prevent collisions.
  • Audit existing group assignments in Jenkins to identify any groups that may have inadvertently received privileged permissions and revoke those permissions if necessary.

Generated by OpenCVE AI on September 3, 2026 at 11:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Microsoft Entra Id Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Microsoft Entra Id Plugin

Thu, 03 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Entra Group Permission Collision in Jenkins Plugin Enables Privilege Escalation

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.
References

Subscriptions

Jenkins Project Jenkins Microsoft Entra Id Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-02T16:55:52.930Z

Reserved: 2026-09-01T21:55:27.035Z

Link: CVE-2026-84672

cve-icon Vulnrichment

Updated: 2026-09-02T16:55:45.615Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T16:17:31.833

Modified: 2026-09-03T17:13:16.490

Link: CVE-2026-84672

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T16:00:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key