CVE-2026-92138: Jenkins Bitbucket Server Integration Plugin vulnerability
Published Sep 16, 2026
·Updated
The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the oauthcallback URL from the submitted form rather than from the server-side stored request token, allowing attackers to hijack the OAuth flow and obtain an access token on behalf of the victim.
Affected Software
1 affected component
Jenkins Bitbucket Server Integration Plugin<=6.0.1
Event History
Sep 16, 2026
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker needs to manipulate the oauth_callback URL submitted to the OAuth authorization endpoint. This can redirect the OAuth flow and allow the attacker to obtain an access token on behalf of the victim.
2
Which plugin versions are affected?
Jenkins Bitbucket Server Integration Plugin version 6.0.1 and earlier is affected.