SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84665

HIGH · CVSS 8 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Jenkins SonarQube Scanner Plugin versions 2.18.3 and earlier are vulnerable due to insufficient restrictions on URL schemes for dashboard links, permitting the use of the `javascript:` scheme. This flaw enables stored cross-site scripting (XSS) attacks, which can be exploited by users with Item/Configure permissions to execute malicious scripts. Organizations using this plugin should prioritize remediation to protect against potential exploitation of this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84665
Severity
HIGH
CVSS
8
EPSS
0.24%
Jenkins Java

Original NVD Description

Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.