CVE-2026-42519
medium
CVSS v3
4.3
CVSS v2
—
VIR risk
4.3
Description
Jenkins Script Security Plugin: Missing permission checks allow enumeration of pending and approved classpaths
Predictions
Exploit likelihood
53%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: jenkinsci-cert@googlegroups.com — https://www.jenkins.io/security/advisory/2026-04-29/#SECURITY-3662
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.jenkins-ci.plugins:script-security | <1402.v94c9ce464861 | 1402.v94c9ce464861 |
| MAVEN | org.jenkins-ci.plugins:script-security | < 1402.v94c9ce464861 | 1402.v94c9ce464861 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| jenkins | script_security | {"endIncluding":"1399.ve6a_66547f6e1"} | |
References
CWEs
CWE-862
Verify integrity in audit chain (admin only). AS-IS.