Back to search
CVE-2026-42519
Published: Apr 29, 2026
Modified: Apr 29, 2026
PUBLISHED
Description
A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overall/Read permission to enumerate pending and approved Script Security classpaths.
| Vendor | Product | Versions |
|---|---|---|
Jenkins Project | Jenkins Script Security Plugin | affected 0 - <= 1399.ve6a_66547f6e1 |
References
Jenkins Security Advisory 2026-04-29
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now