EXPOSURES › CVE-2021-26086
CVE-2021-26086
HIGH ⌖ ON CISA KEV · EXPLOITEDAtlassian Jira Server/Data Center suffered a remote path traversal vulnerability (CVE-2021-26086) allowing file read access to /WEB-INF/web.xml.
This vulnerability enabled remote attackers to read configuration files, exposing sensitive data and potentially facilitating further compromise. DIB organizations using Atlassian Jira Server/Data Center must immediately patch and verify that no unpatched systems remain in production to avoid compliance violations and data exposure.
Shame score — A known path traversal vulnerability that was actively exploited but did not enable remote code execution or zero-day exploitation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.