SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84673

HIGH · CVSS 8.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Customizable Header Plugin for Jenkins versions up to 295.v2544b_ca_19b_97 is vulnerable to a stored cross-site scripting (XSS) attack due to improper handling of SVG icons through Stapler data binding. This flaw allows attackers to inject malicious JavaScript into the plugin's appearance configuration, potentially compromising the integrity of the Jenkins environment. Organizations using this plugin should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-84673
Severity
HIGH
CVSS
8.8
EPSS
0.29%
Jenkins Java

Original NVD Description

Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data binding, allowing attackers to configure a custom SVG icon containing inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability.