CVE-2026-42519 Details
Description
A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overall/Read permission to enumerate pending and approved Script Security classpaths.
A vulnerability exists in the Jenkins Script Security Plugin in versions through 1399.ve6a_66547f6e1, where a missing permission check allows users with Overall/Read permission to enumerate both pending and approved Script Security classpaths. This issue arises because the plugin does not properly validate permissions in an HTTP endpoint, enabling unauthorized access to sensitive classpath information.
Users of the Script Security Plugin should update to version 1402.v94c9ce464861, which addresses this vulnerability by requiring Overall/Administer permission to enumerate Script Security classpaths.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.jenkins.io/security/advisory/2026-04-29/#SECURITY-3662 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| jenkins script security | <= 1399.ve6a_66547f6e1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 6, 2026 | Initial Analysis | [email protected] |
| Apr 29, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | New CVE Received | [email protected] |