CVE-2022-36803

HIGH

Atlassian Jira Align < 10.109.2 - Authenticated Privilege Escalation via MasterUserEdit API

Title source: llm
STIX 2.1

Description

The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox.

References (1)

Core 1
Core References
Permissions Required, Vendor Advisory
https://jira.atlassian.com/browse/JIRAALIGN-4281

Scores

CVSS v3 8.8
EPSS 0.0034
EPSS Percentile 56.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (1)
atlassian/jira_align < 10.109.2
Published Oct 14, 2022
Tracked Since Feb 18, 2026