PT-2026-93781 · Jenkins · Bitbucket Server Integration Plugin

CVE-2026-92138

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Bitbucket Server Integration Plugin versions prior to 6.0.2
Description The OAuth authorization endpoint reads the oauth callback URL from the submitted form instead of using the server-side stored request token. This flaw allows attackers to hijack the OAuth flow and obtain an access token on behalf of a victim.
Recommendations Update Jenkins Bitbucket Server Integration Plugin to version 6.0.2 or later.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92138

Affected Products

Bitbucket Server Integration Plugin