---
id: CVE-2026-92139
title: >-
  Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values
  provided in the webhook payload, including certain URLs, and uses configured
  Bitbucket credentials to connect to those URLs, allowing attackers to capture
  Bit…
summary: >-
  Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values
  provided in the webhook payload, including certain URLs, and uses configured
  Bitbucket credentials to connect to those URLs, allowing attackers to capture
  Bit…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-918
vendor: Jenkins Project
product: Jenkins Bitbucket Push and Pull Request Plugin
affected:
  - jenkins_bitbucket_push_and_pull_request_plugin <= 4.0.1
published: '2026-09-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T13:46:13.937'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92139'
references:
  - url: 'https://www.jenkins.io/security/advisory/2026-09-16/#SECURITY-3980'
    label: jenkinsci-cert@googlegroups.com
tags:
  - nvd
  - cve.org
epss: 0.00248
epssPercentile: 0.1433
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-16T18:35:02.931047Z'
ingestedAt: '2026-09-16T14:57:28.025Z'
---

## Overview

Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
