CVE-2026-42525

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:azure_ad:*:*:*:*:*:jenkins:*:*

History

05 May 2026, 14:25

Type Values Removed Values Added
First Time Jenkins
Jenkins azure Ad
CPE cpe:2.3:a:jenkins:azure_ad:*:*:*:*:*:jenkins:*:*
References () https://www.jenkins.io/security/advisory/2026-04-29/#SECURITY-3760 - () https://www.jenkins.io/security/advisory/2026-04-29/#SECURITY-3760 - Vendor Advisory

30 Apr 2026, 15:13

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-29 14:16

Updated : 2026-05-05 14:25


NVD link : CVE-2026-42525

Mitre link : CVE-2026-42525

CVE.ORG link : CVE-2026-42525


JSON object : View

Products Affected

jenkins

  • azure_ad
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')