Stored Cross-Site Scripting Vulnerability in Jenkins Customizable Header Plugin
CVE-2026-84673
8.8HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 2 September 2026
What is CVE-2026-84673?
The Jenkins Customizable Header Plugin version 295.v2544b_ca_19b_97 and prior is vulnerable to a stored cross-site scripting (XSS) attack. This vulnerability arises from improper handling of Stapler data binding, which allows attackers to overwrite the plugin's appearance configuration. By injecting a custom SVG icon that contains inline JavaScript, an attacker could execute arbitrary scripts in the context of a user's session. This could lead to unauthorized actions or data theft, emphasizing the need for timely updates and security patches.
Affected Version(s)
Jenkins Customizable Header Plugin 0 <= 295.v2544b_ca_19b_97