PT-2026-35919 · Jenkins · Jenkins Microsoft Entra Id (Previously Azure Ad) Plugin

Published

2026-04-29

·

Updated

2026-04-29

·

CVE-2026-42525

CVSS v3.1

4.3

Medium

AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2026-42525

Affected Products

Jenkins Microsoft Entra Id (Previously Azure Ad) Plugin