CVE-2026-42525Disclosure(jenkins / azure_ad)

LOWCVSS 4.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_ad

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
azure_ad

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-29: 3Technical Details · 2026-04-29: 304-29
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-42525 Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform ph… https://www.cve.org/CVERecord?id=CVE-2026-42525 ----- Traducción: CVE-2026-42525 Jen… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-42525 for the Jenkins Microsoft Entra ID plugin, noting an unrestricted redirect URL that could enable phishing, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000062
    74 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42525 Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform ph… https://www.cve.org/CVERecord?id=CVE-2026-42525

    Post summary

    The statement discloses a redirect‑URL flaw in the Jenkins Microsoft Entra ID plugin, providing basic technical details while lacking evidence of PoC, exploitation, or remediation.

    00000176
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42525 Unrestricted Redirect URL in Jenkins Microsoft Entra ID Plugin 666.v6060de32f87d https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42525

    Post summary

    The snippet announces CVE-2026-42525, detailing an unrestricted redirect vulnerability in the Jenkins Microsoft Entra ID Plugin, but provides no PoC, exploit details, or patch information.

    0000074
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjenkinsazure_ad-jenkins-

Explore more