Description
The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the server-side stored request token, allowing attackers to hijack the OAuth flow and obtain an access token on behalf of the victim.
Published: 2026-09-16
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Token Extraction via OAuth Callback Injection
Action: Apply Patch
AI Analysis

Impact

The Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier fails to validate the OAuth callback URL stored server‑side. Instead, it accepts a value supplied in the submitted form, enabling an attacker to redirect the OAuth flow to a malicious endpoint and capture the access token that the victim receives. This flaw allows the attacker to obtain provider tokens on behalf of the victim without requiring privileged access to the Jenkins instance. The vulnerability is a classic example of CWE-345 – Data from Alternate Credentials.

Affected Systems

The vulnerability applies to the Jenkins Bitbucket Server Integration Plugin for Jenkins Project. Versions 6.0.1 and earlier are affected; any release newer than 6.0.1 is presumed to contain the fix.

Risk and Exploitability

The flaw has a CVSS score of 4.2, indicating moderate impact. The EPSS score of less than 1% suggests a very low probability of exploitation in the current threat landscape. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it remotely via the web interface by manipulating the OAuth callback field during the authorization step, which requires only the ability to access the vulnerable plugin endpoint. If successful, the attacker can obtain OAuth access tokens and use them to access the victim’s Bitbucket resources. The impact is limited to the credentials the victim’s account can access, but it can lead to data exposure and potential lateral movement.

Generated by OpenCVE AI on September 18, 2026 at 05:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Jenkins Bitbucket Server Integration Plugin to the latest version that enforces server‑side validation of the oauth_callback URL.
  • If an immediate upgrade is not feasible, disable OAuth integration for the affected plugin until a patch is available.
  • Review and revoke any OAuth tokens that might have already been compromised, and monitor logs for suspicious token issuance events.

Generated by OpenCVE AI on September 18, 2026 at 05:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Bitbucket Server Integration Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Bitbucket Server Integration Plugin

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-345
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the server-side stored request token, allowing attackers to hijack the OAuth flow and obtain an access token on behalf of the victim.
References

Subscriptions

Jenkins Project Jenkins Bitbucket Server Integration Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-16T18:37:10.327Z

Reserved: 2026-09-15T16:29:44.795Z

Link: CVE-2026-92138

cve-icon Vulnrichment

Updated: 2026-09-16T18:37:03.464Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:15.773

Modified: 2026-09-18T13:46:13.937

Link: CVE-2026-92138

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:15:03Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity