OAuth Plugin Vulnerability in Jenkins Affects Bitbucket Integration
CVE-2026-48924

4.3MEDIUM

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
27 May 2026

What is CVE-2026-48924?

The Jenkins Bitbucket OAuth Plugin, up to version 0.17, contains a flaw that fails to validate redirect URLs post-login. This oversight can be exploited by attackers to redirect users to malicious sites, enabling phishing attacks. It is crucial for users to be aware of this vulnerability to safeguard their credentials and sensitive information.

Affected Version(s)

Jenkins Bitbucket OAuth Plugin 0 <= 0.17

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.