CVE-2021-26081

MEDIUM

Atlassian Jira Server/Jira Data Center <8.5.14, <8.6.0-8.13.6, <8.1...

Title source: llm
STIX 2.1

Description

REST API in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to enumerate usernames via a Sensitive Data Exposure vulnerability in the `/rest/api/latest/user/avatar/temporary` endpoint.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-72499

Scores

CVSS v3 5.3
EPSS 0.0051
EPSS Percentile 66.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

Status published
Products (4)
atlassian/data_center < 8.5.14
atlassian/jira < 8.5.14
atlassian/jira_data_center 8.6.0 - 8.13.6
atlassian/jira_server 8.6.0 - 8.13.6
Published Jul 20, 2021
Tracked Since Feb 18, 2026