CVE-2021-26086

Atlassian Jira Server, Atlassian Jira Data Center

Published 16 Aug 2021 · updated 17 Jun 2026 · Analyzed

5.3 Medium · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 12 Nov 2024, with a remediation deadline of 3 Dec 2024 for US federal agencies.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.

References