Intel

AIKIDO-2026-328968

azure-ad is vulnerable to Privilege Escalation

Privilege EscalationCVE-2026-84672 Published Today

88

High Risk

This Affects:

JAVAazure-ad
0.0.1 - 710
Fixed in 711
Are you affected? Scan for Free

TL;DR

Microsoft Entra ID Plugin grants group permissions based on both object ID and display name. Because display names are not globally unique and may be attacker-controlled in a tenant, an attacker can create a colliding group name and inherit privileged Jenkins permissions. The fix grants Entra group permissions only by unique object ID.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and authorization grants rely on Microsoft Entra group mappings.

Background info

azure-ad is vulnerable to Privilege Escalation in versions 0.0.1 - 710.

How to fix this

Upgrade the org.jenkins-ci.plugins:azure-ad library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform