CVE-2026-92139 PUBLISHED

Assigner: jenkins
Reserved: 15.09.2026 Published: 16.09.2026 Updated: 16.09.2026

Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.

Product Status

Vendor Jenkins Project
Product Jenkins Bitbucket Push and Pull Request Plugin
Versions Default: unaffected
  • affected from 0 to 4.0.1 (incl.)

References