Junglewise Threat Intelligence

CVE-2026-41103: Microsoft SSO Plugin for Jira & Confluence privilege escalation

CVE-2026-41103 · Severity: critical · CVSS 9.1 · Published 2026-05-12

Vendors: Microsoft.

Executive brief

A vulnerability in the Microsoft Single Sign-On (SSO) plugin for Jira and Confluence could allow an unauthorized person to gain elevated access levels over the network. This plugin is used to manage user logins for popular collaboration and project management tools. If exploited, an attacker could bypass security controls to access sensitive corporate data or perform administrative actions within these platforms.

Technical details

The Microsoft SSO Plugin for Jira & Confluence contains a vulnerability classified as an incorrect implementation of an authentication algorithm (CWE-303). The flaw exists within the authentication logic, allowing a remote, unauthenticated attacker to bypass standard security checks and elevate their privileges. The attack can be carried out over the network without any user interaction or prior administrative rights. This could lead to a complete compromise of confidentiality and integrity within the affected Jira or Confluence instances. Users are advised to consult the Microsoft Security Response Center for patch availability.

Affected products

  • Microsoft SSO Plugin for Jira & Confluence

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References