SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84672

HIGH · CVSS 8.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Jenkins Microsoft Entra ID Plugin versions up to 710.v0b_ff8e9cc2d2 are vulnerable due to improper handling of group permissions, allowing attackers to exploit name collisions in Entra groups to gain unauthorized access to privileged group permissions. This high-severity vulnerability poses a significant risk to organizations using Jenkins with Microsoft Entra ID for identity management. Organizations utilizing this plugin should prioritize immediate remediation to mitigate potential unauthorized access and privilege escalation risks.

CVE
CVE-2026-84672
Severity
HIGH
CVSS
8.8
EPSS
0.24%
Microsoft Jenkins

Original NVD Description

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.