PT-2026-93781 · Jenkins · Bitbucket Server Integration Plugin
CVE-2026-92138
·
Published
2026-09-16
·
Updated
2026-09-16
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Bitbucket Server Integration Plugin versions prior to 6.0.2
Description
The OAuth authorization endpoint reads the
oauth callback URL from the submitted form instead of using the server-side stored request token. This flaw allows attackers to hijack the OAuth flow and obtain an access token on behalf of a victim.Recommendations
Update Jenkins Bitbucket Server Integration Plugin to version 6.0.2 or later.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bitbucket Server Integration Plugin