CVE-2026-84665
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 02, 2026
Vendor
unknown
Description
Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.