Security Flaw in Jenkins Matrix Authorization Strategy Plugin Affects Multiple Versions
CVE-2026-42521

6.5MEDIUM

What is CVE-2026-42521?

An issue in the Matrix Authorization Strategy Plugin allows unauthorized users with specific permissions to invoke parameterless constructors of classes when deserializing inheritance strategies. This flaw could potentially lead to the instantiation of arbitrary types, posing risks of information disclosure or other adverse effects, depending on the classes available on the classpath. Proper restrictions on which classes can be instantiated are necessary to mitigate this security risk.

Affected Version(s)

Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 <= 3.2.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.