CVE Database · CVE-2021-26086
CVSS v3.1
5.3
EPSS
100.00%
Published
Aug 15, 2021
Modified
Oct 24, 2025
CISA Known Exploited Vulnerability
Added: 2024-11-12 · Due: 2024-12-03
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Public PoC / Exploit (6)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NWeaknesses (CWE)
Affected Products (6)
References (5)