Improper Authorization Vulnerability in Jira Service Management Data Center by Atlassian
CVE-2026-21587

7.1HIGH

Key Information:

Vendor

Atlassian

Vendor
CVE Published:
15 September 2026

What is CVE-2026-21587?

An improper authorization vulnerability was identified in Jira Service Management Data Center, which could potentially allow an authenticated attacker to access unauthorized resources. This vulnerability may lead to the unintentional exposure of sensitive information or enable the execution of arbitrary code. Atlassian encourages users to upgrade to the latest version or one of the specified fixed versions above 11.3.11 to mitigate the risks associated with this vulnerability. For more details, refer to the release notes and download the fix from Atlassian's official sites.

Affected Version(s)

Jira Service Management Data Center 11.3.0 to 11.3.10

Jira Service Management Data Center 11.3.11

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.