Junglewise Threat Intelligence

CVE-2026-21587: Atlassian Jira Service Management Data Center improper authorization

CVE-2026-21587 · Severity: info · CVSS 7.1 · Published 2026-09-15

Executive brief

Jira Service Management Data Center is a popular platform for managing IT service requests and customer support workflows used by organizations worldwide. An improper authorization flaw allows authenticated users to gain unauthorized access to resources and functionality they should not have, potentially exposing sensitive information or enabling attackers to take administrative actions on the system.

Technical details

This improper authorization vulnerability in Jira Service Management Data Center was introduced in version 11.3.0 and affects versions 11.3.0 through 11.3.10. The flaw allows an authenticated attacker to bypass access controls and gain unintended access to resources or functionality. The vulnerability requires network access and prior authentication but does not require user interaction. An attacker can exploit this to access sensitive information or potentially execute arbitrary code. The fix is available in version 11.3.11 and later.

Affected products

  • Atlassian Jira Service Management Data Center 11.3.0 to 11.3.10

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in version 11.3.11 and later

References