Description
This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center.

This Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code.

Atlassian recommends that Jira Service Management Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:

* Jira Service Management Data Center 11.3: Upgrade to a release greater than or equal to 11.3.11



See the release notes (https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html). You can download the latest version of Jira Service Management Data Center from the download center (https://www.atlassian.com/software/jira/service-management/download-archives).

This vulnerability was reported via our Penetration Testing program.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access and Potential Code Execution
Action: Immediate Patch
AI Analysis

Impact

Atlassian Jira Service Management Data Center introduced an Improper Authorization flaw in version 11.3.0 that permits an authenticated user to access data or functions beyond the user’s intended privileges. The vulnerability can expose sensitive information or allow the attacker to execute commands when the exposed functionality supports arbitrary code execution-285, which means the application failed to enforce sufficient authorization checks on protected resources.

Affected Systems

The affected product is Atlassian Jira Service Management Data Center, specifically any deployment of version 11.3.0 through 11.3.10. Versions 11.3.11 and later include the remediation. Customers running the younger release should plan to upgrade to the current version suite available from the Atlassian download center.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity level, while the EPSS score is < 1% and the vulnerability is not recorded in CISA's KEV catalog authenticated within the system; once authenticated, the elevated access can provide a wide attack surface. Given the EPSS score of < 1%, the probability of exploitation is low but the impact remains significant for organizations that have not applied the available patch.

Generated by OpenCVE AI on September 17, 2026 at 12:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Atlassian Jira Service Management Data Center to version 11.3.11 for the Improper Authorization vulnerability.
  • If an immediate upgrade is not possible, schedule an upgrade during a maintenance window and verify that the instance uses a supported fixed version.
  • After the upgrade, review user role configurations to enforce least privilege and ensure that no users possess unintended access rights.

Generated by OpenCVE AI on September 17, 2026 at 12:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Atlassian Jira Service Management Data Center Allows Elevated Access

Wed, 16 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Atlassian Jira Service Management Data Center Allows Elevated Access

Tue, 15 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code. Atlassian recommends that Jira Service Management Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Jira Service Management Data Center 11.3: Upgrade to a release greater than or equal to 11.3.11 See the release notes (https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html). You can download the latest version of Jira Service Management Data Center from the download center (https://www.atlassian.com/software/jira/service-management/download-archives). This vulnerability was reported via our Penetration Testing program.
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published:

Updated: 2026-09-17T11:58:30.920Z

Reserved: 2026-01-01T00:00:40.722Z

Link: CVE-2026-21587

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:20.651Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T17:17:11.893

Modified: 2026-09-17T12:17:31.640

Link: CVE-2026-21587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T13:00:08Z

Weaknesses