cbcvebase.
CVE-2026-42525
published 2026-04-29

CVE-2026-42525: Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to…

medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

Affected

14 ranges
VendorProductVersion rangeFixed in
jenkinsazure_ad<= 666.v6060de32f87d
jenkinscredentials_binding
jenkinscredentials_binding_plugin
jenkinsgithub
jenkinsgithub_branch_source
jenkinsgithub_branch_source_plugin
jenkinsgithub_plugin
jenkinshtml_publisher
jenkinshtml_publisher_plugin
jenkinsmatrix_authorization_strategy
jenkinsmatrix_authorization_strategy_plugin
jenkinsscript_security
jenkinsscript_security_plugin
jenkins_projectjenkins_microsoft_entra_id_plugin<= 666.v6060de32f87d