SonarQube Docker Images Blank Root Password Vulnerability Allowing Privilege Escalation

Vulnerability

A vulnerability exists in official SonarQube Docker images prior to Alpine that allows remote access to the root user with a blank password. This issue arises from the images being deployed with an empty password configuration for the root user, potentially enabling unauthorized users to gain root access on the host system.

Impact

Exploitation of this vulnerability allows for unauthorized root access on the host system where the affected SonarQube Docker container is running.

Added: Jun 22, 2026, 11:26 AM
Updated: Jun 22, 2026, 11:26 AM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
7.9
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.