OAuth Vulnerability in Jenkins Bitbucket Server Integration Plugin
CVE-2026-92138

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92138?

The Jenkins Bitbucket Server Integration Plugin, specifically versions 6.0.1 and earlier, presents a security flaw within its OAuth authorization endpoint. Instead of securely retrieving the oauth_callback URL from a server-side stored request token, it improperly reads this information from the submitted form. This vulnerability can be exploited by attackers to hijack the OAuth flow, allowing them to acquire an access token that could enable unauthorized access to user accounts and sensitive data.

Affected Version(s)

Jenkins Bitbucket Server Integration Plugin 0 <= 6.0.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.