Skip to content
COOEY

EXPOSURES › CVE-2021-26086

CVE-2021-26086

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-11-12 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-26086 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatched

Atlassian Jira Server/Data Center suffered a remote path traversal vulnerability (CVE-2021-26086) allowing file read access to /WEB-INF/web.xml.

This vulnerability enabled remote attackers to read configuration files, exposing sensitive data and potentially facilitating further compromise. DIB organizations using Atlassian Jira Server/Data Center must immediately patch and verify that no unpatched systems remain in production to avoid compliance violations and data exposure.

Shame score — A known path traversal vulnerability that was actively exploited but did not enable remote code execution or zero-day exploitation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.