Stored Cross-Site Scripting Vulnerability in Jenkins SonarQube Scanner Plugin
CVE-2026-84665

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
2 September 2026

What is CVE-2026-84665?

The Jenkins SonarQube Scanner Plugin versions 2.18.3 and earlier is vulnerable due to the lack of URL scheme restrictions for dashboard links generated from SonarQube scanner results. This oversight permits the inclusion of the 'javascript:' scheme, enabling potential exploitation through stored cross-site scripting (XSS). Attackers with Item/Configure permissions can leverage this vulnerability to execute arbitrary JavaScript code in the context of other users, compromising their data and session integrity.

Affected Version(s)

Jenkins SonarQube Scanner Plugin 0 <= 2.18.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.