PT-2026-35915 · Jenkins · Matrix Authorization Strategy Plugin

Arafat Ul Islam

+1

·

Published

2026-04-29

·

Updated

2026-04-29

·

CVE-2026-42521

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Matrix Authorization Strategy Plugin versions 2.0-beta-1 through 3.2.9
Description The plugin invokes parameterless constructors of classes specified in the configuration during the deserialization of inheritance strategies. Because it does not restrict the classes that can be instantiated, users with Item/Configure permission can instantiate arbitrary types. This may result in information disclosure or other impacts depending on the classes available on the classpath.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42521
GHSA-JP9R-MMHW-VFF3

Affected Products

Matrix Authorization Strategy Plugin