CVE-2026-42525

MEDIUM

Jenkins Microsoft Entra ID Plugin <=666.v6060de32f87d - Open Redirect

Title source: llm
STIX 2.1

Description

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 7.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (1)
Jenkins Project/Jenkins Microsoft Entra ID (previously Azure AD) Plugin < 666.v6060de32f87d
Published Apr 29, 2026
Tracked Since Apr 29, 2026