Junglewise Threat Intelligence

CVE-2021-26086: Atlassian Jira Server and Data Center Path Traversal Vulnerability

CVE-2021-26086 · Severity: critical · CVSS 5.3 · Exploited in the wild · Published 2024-11-12

Technologies: Atlassian Data Center. Vendors: Atlassian.

Executive brief

Atlassian Jira Server and Data Center are vulnerable to path traversal via the /WEB-INF/web.xml endpoint. A remote, unauthenticated attacker can exploit this to read sensitive configuration files. This vulnerability has been observed being exploited in the wild.

Affected products

  • Atlassian Jira Server < 8.5.14, 8.6.0 to < 8.13.6, 8.14.0 to < 8.16.1
  • Atlassian Jira Data Center < 8.5.14, 8.6.0 to < 8.13.6, 8.14.0 to < 8.16.1

Timeline

  • 2021-08-30: disclosed: Initial NVD analysis date
  • 2024-11-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-11-12: exploited: Confirmed as exploited in the wild per CISA KEV entry

Related threats