CVE-2026-42521
Severity CVSS v4.0:
Pending analysis
Type:
CWE-502
Deserialization of Untrusted Dat
Publication date:
29/04/2026
Last modified:
06/05/2026
Description
Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategies, without restricting the classes that can be instantiated, allowing attackers with Item/Configure permission to instantiate arbitrary types, which may lead to information disclosure or other impacts depending on the classes available on the classpath.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:jenkins:matrix_authorization_strategy:*:*:*:*:*:jenkins:*:* | 2.1 (including) | 3.2.10 (excluding) |
| cpe:2.3:a:jenkins:matrix_authorization_strategy:2.0:beta1:*:*:*:jenkins:*:* | ||
| cpe:2.3:a:jenkins:matrix_authorization_strategy:2.0:beta2:*:*:*:jenkins:*:* | ||
| cpe:2.3:a:jenkins:matrix_authorization_strategy:2.0:beta3:*:*:*:jenkins:*:* |
To consult the complete list of CPE names with products and versions, see this page



