ZeroHour

CVE-2021-26086

KEV PoC mass

Path Traversal File Read in Atlassian Jira Server and Data Center

CISA: Atlassian Jira Server and Data Center Path Traversal Vulnerability

CVSS 3.1
5.3 medium
EPSS
100%p100
Published
()
KEV added
AI analysis

Atlassian Jira Server and Data Center contain a path traversal flaw (CWE-22) in the /WEB-INF/web.xml endpoint that lets a remote attacker read particular files by sending crafted requests containing traversal sequences. Triggering requires only HTTP access to the affected endpoint on a vulnerable, self-hosted Jira instance; an attacker gains disclosure of specific files, an information-exposure condition that can aid further reconnaissance rather than full system compromise. Organizations running self-hosted Jira Server or Data Center are affected, while Atlassian Cloud is out of scope of this product listing. Exploitation is confirmed by CISA's inclusion of the bug in the Known Exploited Vulnerabilities catalog on 2024-11-12, and a top-percentile EPSS score of 100% indicates near-certain exploitation activity within 30 days; no public proof-of-concept is cataloged and ransomware association is listed as unknown.

What to do: Upgrade self-hosted Jira Server and Data Center to the fixed releases specified in Atlassian's advisory for CVE-2021-26086, since the provided data does not include exact version ranges. Audit internet-facing Jira instances for access to the /WEB-INF/web.xml endpoint and restrict or front-end Jira with access controls where patching must be delayed. Federal agencies must apply the vendor mitigation or discontinue use per the CISA KEV required action.

Affected
Atlassian Jira Server and Data Center
Estimated exposure
mass≈100,000+ internet-exposed self-hosted Jira instances (public scan counts), with millions of users on self-hosted Jira overall — Public internet scans have historically cataloged on the order of 100k Jira Server/Data Center instances, and Atlassian's self-hosted installed base spans tens of thousands of customer deployments with a large user population, though many…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.

CISA Known Exploited Vulnerability
Affected
Atlassian Jira Server and Data Center
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
atlassian
Products
jira data center, jira server
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news