CVE-2021-26086
KEV PoC massPath Traversal File Read in Atlassian Jira Server and Data Center
CISA: Atlassian Jira Server and Data Center Path Traversal Vulnerability
Atlassian Jira Server and Data Center contain a path traversal flaw (CWE-22) in the /WEB-INF/web.xml endpoint that lets a remote attacker read particular files by sending crafted requests containing traversal sequences. Triggering requires only HTTP access to the affected endpoint on a vulnerable, self-hosted Jira instance; an attacker gains disclosure of specific files, an information-exposure condition that can aid further reconnaissance rather than full system compromise. Organizations running self-hosted Jira Server or Data Center are affected, while Atlassian Cloud is out of scope of this product listing. Exploitation is confirmed by CISA's inclusion of the bug in the Known Exploited Vulnerabilities catalog on 2024-11-12, and a top-percentile EPSS score of 100% indicates near-certain exploitation activity within 30 days; no public proof-of-concept is cataloged and ransomware association is listed as unknown.
What to do: Upgrade self-hosted Jira Server and Data Center to the fixed releases specified in Atlassian's advisory for CVE-2021-26086, since the provided data does not include exact version ranges. Audit internet-facing Jira instances for access to the /WEB-INF/web.xml endpoint and restrict or front-end Jira with access controls where patching must be delayed. Federal agencies must apply the vendor mitigation or discontinue use per the CISA KEV required action.
| Atlassian Jira Server and Data Center | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.
- Affected
- Atlassian Jira Server and Data Center
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- atlassian
- Products
- jira data center, jira server
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N