← Vulnerability feed

Vulnerability record · CVE-2020-36239 · published 29 July 2021

CVE-2020-36239: Atlassian Jira Data Center Ehcache RMI service missing authentication RCE

Atlassian · Jira Data Center

Jira Data Center, Jira Core Data Center, Jira Software Data Center and Jira Service Management Data Center exposed an Ehcache RMI network service on port 40001 (and potentially 40011) without authentication. An attacker able to reach that port can deserialize untrusted data and execute arbitrary code in the Jira process. Fixed versions require a shared secret to access the Ehcache service.

9.8 CVSS 3.1 Critical EPSS 50% · top 1.1% CWE-862 · Missing authorizationCWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score, v2 7.5
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 exposed a Ehcache RMI network service which attackers, who can connect to the service, on port 40001 and potentially 40011[0][1], could execute arbitrary code of their choice in Jira through deserialization due to a missing authentication vulnerability. While Atlassian strongly suggests restricting access to the Ehcache ports to only Data Center instances, fixed versions of Jira will now require a shared secret in order to allow access to the Ehcache service. [0] In Jira Data Center, Jira Core Data Center, and Jira Software Data Center versions prior to 7.13.1, the Ehcache object port can be randomly allocated. [1] In Jira Service Management Data Center versions prior to 3.16.1, the Ehcache object port can be randomly allocated.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required and a high EPSS score make this a top-priority remote code execution exposure for internet- or network-reachable Jira Data Center instances.

What it is

Jira Data Center, Jira Core Data Center, Jira Software Data Center and Jira Service Management Data Center exposed an Ehcache RMI network service on port 40001 (and potentially 40011) without authentication. An attacker able to reach that port can deserialize untrusted data and execute arbitrary code in the Jira process. Fixed versions require a shared secret to access the Ehcache service.

Impact

An unauthenticated network attacker gains arbitrary code execution in the Jira server process, which typically runs with the application's privileges and can lead to full compromise of the instance and its data.

Attack surface

Reached over the network via the exposed Ehcache RMI ports 40001 and potentially 40011; the CVSS vector shows no privileges or user interaction required. In some older versions the Ehcache object port is randomly allocated, so the exact port may vary.

Exploitation

Not listed in CISA KEV and no ransomware association is documented, but EPSS is high at roughly 0.50 (98.8th percentile), indicating substantial predicted exploitation activity; references are vendor advisories and patch links only.

What to do

  • Upgrade to a fixed Jira/Jira Service Management Data Center release (8.5.16, 8.13.8, 8.17.0 or later for Jira; 4.5.16, 4.13.8, 4.17.0 or later for Jira Service Management) so the Ehcache service requires a shared secret.
  • Restrict network access to the Ehcache ports (40001 and 40011, or the randomly allocated object port) to only trusted Data Center cluster nodes.
  • Block the Ehcache ports at the perimeter and between network segments so they are not reachable from untrusted networks.
  • If immediate patching is not possible, isolate affected instances and monitor for unexpected connections to the Ehcache ports.

Detection

  • Monitor network traffic and firewall logs for inbound connections to TCP 40001 and 40011 from hosts outside the Jira cluster.
  • Alert on unexpected processes or child processes spawned by the Jira Java process.
  • Review Jira and host logs for deserialization errors or unusual RMI/Ehcache activity around the service ports.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-36239 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.3CVE-2021-26086Atlassian Jira Server and Data Center path traversal file readJira Server and Data Center contain a path traversal flaw in the /WEB-INF/web.xml endpoint that lets remote attackers read particular files. The affe…KEVEPSS 100%analysed9.8CVE-2022-26136Atlassian bamboo improper authentication vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps…EPSS 5.4%9.8CVE-2022-0540Atlassian Jira Seraph authentication bypass via crafted HTTP requestJira Server, Data Center and Jira Service Management contain an authentication bypass in the Seraph component, reachable by sending a specially craft…EPSS 88%analysed9.8CVE-2019-13990Softwareag quartz xml external entity (xxe) vulnerabilityinitDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.EPSS 16%9.1CVE-2023-22501Atlassian jira service management improper authentication vulnerabilityAn authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user…EPSS 16%8.8CVE-2024-21683Atlassian Confluence Data Center and Server code injection RCEConfluence Data Center and Server contain a code injection flaw introduced in version 5.2 that allows an authenticated attacker to execute arbitrary …EPSS 88%analysed8.8CVE-2022-26137Atlassian bamboo origin validation error vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the a…EPSS 2.3%8.7CVE-2025-22167Atlassian jira data center path traversal vulnerabilityThis High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Sof…EPSS 0.50%

Source: NIST National Vulnerability Database (record CVE-2020-36239), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.