SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2021-26076

LOW · CVSS 3.7 EPSS 1.23%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-04-15 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 3.7. It may be remotely exploitable.

CVE
CVE-2021-26076
Severity
LOW
CVSS
3.7
EPSS
1.23%

Original NVD Description

The jira.editor.user.mode cookie set by the Jira Editor Plugin in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.0 allows remote anonymous attackers who can perform an attacker in the middle attack to learn which mode a user is editing in due to the cookie not being set with a secure attribute if Jira was configured to use https.

Related CVEs

Other vulnerabilities affecting the same vendor(s)