Stored Cross-Site Scripting Vulnerability in Jenkins SonarQube Scanner Plugin
CVE-2026-84665
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 2 September 2026
What is CVE-2026-84665?
The Jenkins SonarQube Scanner Plugin versions 2.18.3 and earlier is vulnerable due to the lack of URL scheme restrictions for dashboard links generated from SonarQube scanner results. This oversight permits the inclusion of the 'javascript:' scheme, enabling potential exploitation through stored cross-site scripting (XSS). Attackers with Item/Configure permissions can leverage this vulnerability to execute arbitrary JavaScript code in the context of other users, compromising their data and session integrity.
Affected Version(s)
Jenkins SonarQube Scanner Plugin 0 <= 2.18.3