← Vulnerability feed

Vulnerability record · CVE-2019-11581 · published 9 August 2019

CVE-2019-11581: Atlassian Jira Server and Data Center server-side template injection

Atlassian · Jira Server

Jira Server and Data Center contain a server-side template injection flaw in the ContactAdministrators and SendBulkMail actions. An attacker can inject template expressions that are evaluated server-side, leading to remote code execution on vulnerable installations. The affected range spans many releases from 4.4.0 up to before 8.2.3, so unpatched deployments are broadly exposed.

9.8 CVSS 3.1 Critical CISA KEV since 7 Mar 2022 EPSS 85% · top 0.3% CWE-74 · Injection
9.8CVSS 3.1 base score, v2 9.3
85%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction, active exploitation per CISA KEV, and a very high EPSS probability make this an urgent patching priority.

What it is

Jira Server and Data Center contain a server-side template injection flaw in the ContactAdministrators and SendBulkMail actions. An attacker can inject template expressions that are evaluated server-side, leading to remote code execution on vulnerable installations. The affected range spans many releases from 4.4.0 up to before 8.2.3, so unpatched deployments are broadly exposed.

Impact

Successful exploitation gives the attacker remote code execution on the Jira host, allowing full compromise of confidentiality, integrity and availability of the application and its data.

Attack surface

The flaw is reachable over the network through the ContactAdministrators and SendBulkMail actions, with no authentication or user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

The vulnerability is listed in CISA KEV with a 2022-03-07 addition date, and EPSS reports a 30-day exploitation probability of 0.84621 (99.7th percentile), indicating active exploitation in the wild. No ransomware campaign use is documented in the record.

What to do

  • Upgrade Jira Server and Data Center to a fixed release: 7.6.14, 7.13.5, 8.0.3, 8.1.2 or 8.2.3 depending on your branch.
  • If immediate patching is not possible, restrict network access to the Jira instance and disable or block the ContactAdministrators and SendBulkMail functionality.
  • Monitor Atlassian advisories and the JRASERVER-69532 ticket for updated guidance and any backported fixes.
  • Verify no unauthorized administrative accounts or outbound connections exist on Jira hosts, and rotate credentials if compromise is suspected.

Detection

  • Review Jira application and access logs for unusual requests to ContactAdministrators and SendBulkMail endpoints, especially with template-like payloads.
  • Hunt for unexpected child processes spawned by the Jira Java process (for example shells or scripting interpreters).
  • Monitor for outbound network connections from Jira servers to unfamiliar hosts that could indicate post-exploitation activity.
  • Check for anomalous file writes or new files in Jira web directories and temporary paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-11581 to the Known Exploited Vulnerabilities catalog on 7 March 2022 as "Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 7 September 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-11581 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.3CVE-2021-26086Atlassian Jira Server and Data Center path traversal file readJira Server and Data Center contain a path traversal flaw in the /WEB-INF/web.xml endpoint that lets remote attackers read particular files. The affe…KEVEPSS 100%analysed9.8CVE-2022-26136Atlassian bamboo improper authentication vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps…EPSS 5.4%9.8CVE-2022-0540Atlassian Jira Seraph authentication bypass via crafted HTTP requestJira Server, Data Center and Jira Service Management contain an authentication bypass in the Seraph component, reachable by sending a specially craft…EPSS 88%analysed8.8CVE-2024-21683Atlassian Confluence Data Center and Server code injection RCEConfluence Data Center and Server contain a code injection flaw introduced in version 5.2 that allows an authenticated attacker to execute arbitrary …EPSS 88%analysed8.8CVE-2022-26137Atlassian bamboo origin validation error vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the a…EPSS 2.3%8.7CVE-2025-22167Atlassian jira data center path traversal vulnerabilityThis High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Sof…EPSS 0.50%8.1CVE-2019-8443Atlassian jira improper authentication vulnerabilityThe ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows …EPSS 2.6%7.8CVE-2019-20419Atlassian jira data center uncontrolled search path element vulnerabilityAffected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hijacking vulnerability in Tomc…EPSS 0.81%

Source: NIST National Vulnerability Database (record CVE-2019-11581), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.