PT-2026-93782 · Jenkins · Bitbucket Push/Pull Request Plugin

CVE-2026-92139

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Bitbucket Push and Pull Request Plugin versions prior to 4.0.2
Description The plugin trusts values provided in the webhook payload, including specific URLs. It uses configured Bitbucket credentials to connect to these URLs, which allows an attacker to capture the stored Bitbucket credentials by sending a crafted webhook payload.
Recommendations Update the Jenkins Bitbucket Push and Pull Request Plugin to version 4.0.2 or later.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92139

Affected Products

Bitbucket Push/Pull Request Plugin