Webhook Manipulation in Jenkins Bitbucket Push and Pull Request Plugin
CVE-2026-92139

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92139?

The Jenkins Bitbucket Push and Pull Request Plugin version 4.0.1 and earlier contains a security flaw that allows unauthenticated attackers to exploit vulnerabilities within trusted values in the webhook payload. Specifically, attackers can craft malicious webhook payloads that exploit the plugin’s functionality, leading to potential exposure of Bitbucket credentials stored within the Jenkins environment. By leveraging this vulnerability, attackers can connect to specified URLs using the stored Bitbucket credentials, compromising the security of the Jenkins instance.

Affected Version(s)

Jenkins Bitbucket Push and Pull Request Plugin 0 <= 4.0.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.