CVE-2021-26086General(atlassian / jira_data_center)

LOWCVSS 5.3 · MEDIUMCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-12-03. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jira_data_center
  • jira_server

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-30); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
jira_data_centerjira_server

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 103-3003-31
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Patrick Roland@DeusLogica
    General

    🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2021-26086 (EPSS 94.00%) Atlassian Jira Server and Data Center path traversal allows remote attackers to read arbitrary files. Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2021-26086 #EPSS #threatintel #CVE #cybersecurity

    Post summary

    The tweet shares an EPSS risk rating and a link to the NVD entry for CVE‑2021‑26086, noting its path traversal nature but offers no evidence of exploitation, PoC, or mitigation.

    1000037
    311 followersView on X
  • Patrick Roland@DeusLogica
    General

    Timestamp: 2026-03-30T11:11:47.242015 Type: HIGH_EPSS Severity: CRITICAL Confidence: MEDIUM Source Reliability: B Title: CVE-2021-26086 (EPSS 94.00%) ## Draft Post 🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2021-26086 (EPSS 94.00%) Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the / Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2021-26086 #EPSS #threatintel #CVE #cybersecurity ## CTI Metadata - Confidence Level: MEDIUM - Source Reliability: B - Calibrated Language: medium confidence

    Post summary

    The post highlights CVE-2021-26086 as a high EPSS path traversal flaw in Atlassian Jira, suggesting likely exploitation, but lacks proof of active attacks, PoC, or mitigation details.

    1000042
    307 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appatlassianjira_data_center---
Appatlassianjira_server---

Explore more