Junglewise Threat Intelligence

CVE-2026-84673: Jenkins Customizable Header Plugin stored XSS in icon configuration

CVE-2026-84673 · Severity: high · CVSS 8.8 · Published 2026-09-02

Vendors: Jenkins.

Executive brief

The Jenkins Customizable Header Plugin allows administrators to configure the appearance of the Jenkins interface, including custom icons. A vulnerability in versions 295.v2544b_ca_19b_97 and earlier permits unauthenticated attackers to overwrite this configuration with malicious SVG icons containing JavaScript code. When other users access Jenkins, the embedded JavaScript executes in their browser, potentially allowing attackers to steal session tokens, modify configurations, or perform actions on behalf of affected users.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw arising from improper input validation in the Customizable Header Plugin's configuration handling. The plugin uses Stapler's data binding mechanism to deserialize and store appearance configuration, but fails to sanitize or restrict the types of objects that can be instantiated or the content of SVG icon fields. An attacker can submit crafted HTTP requests with malicious SVG payloads containing inline JavaScript code that gets persisted in the plugin's configuration. On subsequent page loads, the stored JavaScript executes in the context of any user accessing Jenkins, potentially compromising account security and enabling lateral attacks. The vulnerability is network-accessible and requires no authentication to exploit. Patched versions should implement strict input validation and SVG content filtering to prevent inline scripts.

Affected products

  • Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier

Timeline

  • 2026-09-02: disclosed

References