CVE-2026-21587
moderateImproper Authorization in Jira Service Management Data Center 11.3
CVE-2026-21587 is a high-severity improper authorization (broken access control) flaw affecting Jira Service Management Data Center, introduced in version 11.3.0 and rated 7.1 under CVSS 4.0. An authenticated attacker with low privileges can exploit missing or incorrect authorization checks over the network without user interaction to gain unintended access to resources or functionality. According to Atlassian, this can expose sensitive information and, in some scenarios, allow execution of arbitrary code, with the CVSS vector confirming a high impact on integrity. Only self-hosted Jira Service Management Data Center instances running 11.3.0 through 11.3.10 are affected; Cloud deployments are not. The issue was found through Atlassian's penetration testing program, and no public proof of concept or known in-the-wild exploitation exists at this time.
What to do: Upgrade Jira Service Management Data Center 11.3.x instances to 11.3.11 or the latest version immediately, prioritizing any instance reachable from untrusted networks. Until patched, restrict access via VPN/IP allowlisting and review audit logs for low-privileged accounts accessing resources or functionality outside their expected permissions, including any signs of unexpected code execution.
| Atlassian Jira Service Management Data Center | 11.3.0 to 11.3.10 (fixed in 11.3.11 and later) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code. Atlassian recommends that Jira Service Management Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Jira Service Management Data Center 11.3: Upgrade to a release greater than or equal to 11.3.11 See the release notes (https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html). You can download the latest version of Jira Service Management Data Center from the download center (https://www.atlassian.com/software/jira/service-management/download-archives). This vulnerability was reported via our Penetration Testing program.
- Weakness
- CWE-285
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.