PT-2026-92136 · Atlassian · Jira Service Management Server

CVE-2026-21587

·

Published

2026-09-15

·

Updated

2026-09-17

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Jira Service Management Data Center versions 11.3.0 through 11.3.10
Description An improper authorization issue allows an authenticated attacker to gain unintended access to resources or functionality. This could lead to the exposure of sensitive information or the execution of arbitrary code.
Recommendations Upgrade to version 11.3.11 or a later release.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-21587

Affected Products

Jira Service Management Server