AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-57289

MEDIUM · CVSS 4.8 EPSS 0.11%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-06-24 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.8. It affects Jenkins.

CVE
CVE-2026-57289
Severity
MEDIUM
CVSS
4.8
EPSS
0.11%
Jenkins

Original NVD Description

Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to capture the token.

Related CVEs

Other vulnerabilities affecting the same vendor(s)