CVE-2021-26086
Atlassian Jira Server, Atlassian Jira Data Center
Published 16 Aug 2021 · updated 17 Jun 2026 · Analyzed
5.3 Medium · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 12 Nov 2024, with a remediation deadline of 3 Dec 2024 for US federal agencies.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.
References
- packetstormsecurity.com/files/164405/Atlassian-Jira-Server-Data-Center-8.4.0-File-Read.html · Exploit, Third Party Advisory, VDB Entry
- jira.atlassian.com/browse/JRASERVER-72695 · Issue Tracking, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26086 · US Government Resource