LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-26086: Atlassian Jira Server and Data Center Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 12, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 3, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-26086 to its Known Exploited Vulnerabilities catalog on Nov 12, 2024, with a federal patch deadline of Dec 3, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.

CVE-2021-26086 is a path traversal vulnerability in Atlassian Jira Server and Data Center. It allows a remote attacker to read particular files via the /WEB-INF/web.xml endpoint. For IT and security teams, this matters because Jira often holds project data, credentials in configuration, and other sensitive material; unauthorized file reads can expose that information and enable further compromise. Confirm all version and configuration details against the vendor advisory.

CISA notes the issue and requires applying mitigations per vendor instructions or discontinuing use if mitigations are unavailable. Known ransomware use is not documented for this CVE.

How it works

The weakness is CWE-22, improper limitation of a pathname to a restricted directory (path traversal). In this product class, an attacker crafts requests that manipulate path elements so the application resolves and returns files outside the intended scope. According to the CISA summary, the flaw specifically allows a remote attacker to read particular files through the /WEB-INF/web.xml endpoint.

No further exploit mechanics, payloads, or prerequisites are provided in the available facts. Defenders should treat any unauthenticated or lightly authenticated request that can reach that endpoint as potentially able to retrieve restricted files. Exact conditions, required privileges, and which files are reachable must be confirmed against the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

Atlassian Jira Server and Data Center typically run as on-premises or self-managed instances in enterprise environments—often behind reverse proxies or load balancers, sometimes exposed to the internet for remote teams. Cloud-hosted Jira is outside the scope of this CVE description.

Public detail on exact affected builds is limited to the product names given; always verify against Atlassian’s advisory.

How to remediate

Patch first. Apply the vendor update or mitigation instructions named in the Atlassian advisory for Jira Server and Data Center. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Reduce exposure until the vendor update can be applied.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to breaches because file disclosure often yields credentials, configuration, or other data useful for lateral movement. Known ransomware use is not documented for CVE-2021-26086, but the risk of data exposure remains. Review logs for signs of successful file reads, assume any retrieved secrets are compromised, and rotate them. You can run a free exposure scan of your email addresses against known breach data sets to check whether related accounts appear in public breach collections, then prioritize password resets and multi-factor authentication for any matches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAtlassian · Jira Server and Data Center
WeaknessCWE-22
Added to CISA KEVNov 12, 2024
Federal patch deadlineDec 3, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities