Improper Authentication in Jira Software Data Center - CVE-2026-21582

 

Improper Authentication in Jira Software Data Center - CVE-2026-21582

Published: August 19, 2026


Vulnerability identifier: #VU144403
CSH Severity: High
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-21582
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform actions as another user.

The vulnerability exists due to broken authentication and session management in Jira Data Center when handling authentication and session management. A remote attacker can exploit the authentication and session management flaw to perform actions as another user.

User interaction is required.


Affected software

Jira Software Data Center

How to mitigate CVE-2026-21582

Install security update from vendor's website.

Jira Software Data Center - addressed in versions 9.12.38, 10.3.24, 11.3.10

External References

Related Security Bulletins