Security Flaw in Jenkins Matrix Authorization Strategy Plugin Affects Multiple Versions
CVE-2026-42521
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 29 April 2026
What is CVE-2026-42521?
An issue in the Matrix Authorization Strategy Plugin allows unauthorized users with specific permissions to invoke parameterless constructors of classes when deserializing inheritance strategies. This flaw could potentially lead to the instantiation of arbitrary types, posing risks of information disclosure or other adverse effects, depending on the classes available on the classpath. Proper restrictions on which classes can be instantiated are necessary to mitigate this security risk.
Affected Version(s)
Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 <= 3.2.9