Incorrect Implementation of Authentication Algorithm in Microsoft JIRA SAML SSO plugin and Microsoft Confluence SAML SSO plugin - CVE-2026-41103
Published: May 13, 2026
Vulnerability identifier: #VU131306
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41103
CWE-ID: CWE-303
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence. A remote attacker can gain elevated privileges on the target system.
Affected software
Microsoft JIRA SAML SSO plugin
Microsoft Confluence SAML SSO plugin
Microsoft Confluence SAML SSO plugin
How to mitigate CVE-2026-41103
Install updates from vendor's website.
Microsoft JIRA SAML SSO plugin - update to 1.3.3
Microsoft Confluence SAML SSO plugin - update to 7.4.0
Microsoft Confluence SAML SSO plugin - update to 7.4.0