Webhook Manipulation in Jenkins Bitbucket Push and Pull Request Plugin
CVE-2026-92139
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-92139?
The Jenkins Bitbucket Push and Pull Request Plugin version 4.0.1 and earlier contains a security flaw that allows unauthenticated attackers to exploit vulnerabilities within trusted values in the webhook payload. Specifically, attackers can craft malicious webhook payloads that exploit the plugin’s functionality, leading to potential exposure of Bitbucket credentials stored within the Jenkins environment. By leveraging this vulnerability, attackers can connect to specified URLs using the stored Bitbucket credentials, compromising the security of the Jenkins instance.
Affected Version(s)
Jenkins Bitbucket Push and Pull Request Plugin 0 <= 4.0.1