ZeroHour

CVE-2026-21587

moderate

Improper Authorization in Jira Service Management Data Center 11.3

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-21587 is a high-severity improper authorization (broken access control) flaw affecting Jira Service Management Data Center, introduced in version 11.3.0 and rated 7.1 under CVSS 4.0. An authenticated attacker with low privileges can exploit missing or incorrect authorization checks over the network without user interaction to gain unintended access to resources or functionality. According to Atlassian, this can expose sensitive information and, in some scenarios, allow execution of arbitrary code, with the CVSS vector confirming a high impact on integrity. Only self-hosted Jira Service Management Data Center instances running 11.3.0 through 11.3.10 are affected; Cloud deployments are not. The issue was found through Atlassian's penetration testing program, and no public proof of concept or known in-the-wild exploitation exists at this time.

What to do: Upgrade Jira Service Management Data Center 11.3.x instances to 11.3.11 or the latest version immediately, prioritizing any instance reachable from untrusted networks. Until patched, restrict access via VPN/IP allowlisting and review audit logs for low-privileged accounts accessing resources or functionality outside their expected permissions, including any signs of unexpected code execution.

Affected
Atlassian Jira Service Management Data Center11.3.0 to 11.3.10 (fixed in 11.3.11 and later)
Estimated exposure
moderateLow thousands of self-hosted instances (subset of Jira Service Management Data Center deployments running 11.3.0–11.3.10) — JSM Data Center self-hosts number in the low tens of thousands globally, but the flaw is confined to the recent 11.3 feature stream, which only a fraction of deployments run; many are also internet-facing per public scan data on Jira…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code. Atlassian recommends that Jira Service Management Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Jira Service Management Data Center 11.3: Upgrade to a release greater than or equal to 11.3.11 See the release notes (https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html). You can download the latest version of Jira Service Management Data Center from the download center (https://www.atlassian.com/software/jira/service-management/download-archives). This vulnerability was reported via our Penetration Testing program.

Weakness
CWE-285
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.