VYPR
Medium severity4.3NVD Advisory· Published Apr 29, 2026· Updated May 5, 2026

CVE-2026-42525

CVE-2026-42525

Description

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:azure-adMaven
< 667.v4c5827a667.v4c5827a

Affected products

1
  • cpe:2.3:a:jenkins:azure_ad:*:*:*:*:*:jenkins:*:*
    Range: <=666.v6060de32f87d

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.