cbcvebase.
CVE-2026-48924
published 2026-05-27

CVE-2026-48924: Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.22%
12.0th percentile
Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

Affected

24 ranges
VendorProductVersion rangeFixed in
jenkinsactive_directory
jenkinsactive_directory_plugin
jenkinsappspider
jenkinsappspider_plugin
jenkinsbitbucket_oauth<= 0.17
jenkinsbitbucket_oauth
jenkinsbitbucket_oauth_plugin
jenkinscredentials_binding
jenkinscredentials_binding_plugin
jenkinsemail_extension
jenkinsemail_extension_plugin
jenkinsgithub_integration
jenkinsgithub_integration_plugin
jenkinsgroovy_libraries
jenkinsgroovy_libraries_plugin
jenkinsjob_import
jenkinsjob_import_plugin
jenkinsldap
jenkinsldap_plugin
jenkinsldap_referrals_in_active_directory
jenkinsldap_referrals_in_active_directory_plugin
jenkinsmultijob
jenkinsmultijob_plugin
jenkins_projectjenkins_bitbucket_oauth_plugin<= 0.17

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
vendor_oracle4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.