Vulnerability record · CVE-2022-26135 · published 30 June 2022
CVE-2022-26135: Jira Mobile Plugin batch endpoint full-read SSRF
Atlassian · Jira Data Center
The Mobile Plugin for Jira Data Center and Server exposes a batch endpoint that lets a remote, authenticated user trigger a full read server-side request forgery. Because any account, including one created through the sign-up feature, is sufficient, the flaw gives low-privilege users a way to make the Jira server issue requests on their behalf. It affects Jira Server and Data Center 8.0.0 through 8.22.4 and Jira Management/Service Management 4.0.0 through 4.22.4 per the advisory ranges.
Description
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.20.10, from version 8.21.0 before 8.22.4. This also affects Jira Management Server and Data Center versions from version 4.0.0 before 4.13.22, from version 4.14.0 before 4.20.10 and from version 4.21.0 before 4.22.4.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw is remotely reachable by any authenticated user with no interaction and carries high confidentiality impact, and EPSS is very high even though it is not in KEV.
What it is
The Mobile Plugin for Jira Data Center and Server exposes a batch endpoint that lets a remote, authenticated user trigger a full read server-side request forgery. Because any account, including one created through the sign-up feature, is sufficient, the flaw gives low-privilege users a way to make the Jira server issue requests on their behalf. It affects Jira Server and Data Center 8.0.0 through 8.22.4 and Jira Management/Service Management 4.0.0 through 4.22.4 per the advisory ranges.
Impact
An attacker gains the ability to read responses from requests the Jira server makes to internal or external systems, exposing internal services and data reachable from the Jira host. There is no integrity or availability impact per the CVSS vector; the loss is confidentiality.
Attack surface
Reached over the network through the Mobile Plugin batch endpoint; the attacker must be authenticated but needs no user interaction. The sign-up feature means an attacker can often obtain the required account themselves.
Exploitation
Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is very high at 0.716 (99.4th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade Jira Server/Data Center to 8.13.22, 8.20.10, 8.22.4 or later, and Jira Management/Service Management to 4.13.22, 4.20.10, 4.22.4 or later.
- If immediate patching is not possible, apply the mitigations in Atlassian's 29 June 2022 security advisory, including disabling or restricting the Mobile Plugin.
- Disable self-sign-up or restrict account creation so unvetted users cannot obtain the authenticated access the flaw requires.
- Restrict outbound network access from Jira hosts to only required destinations to limit SSRF reach.
- Audit accounts and remove unused or untrusted users, especially those created via sign-up.
Detection
- Monitor Jira logs for requests to the Mobile Plugin batch endpoint, particularly unusual or repeated calls from low-privilege accounts.
- Alert on outbound connections from Jira hosts to internal RFC1918 addresses, loopback, or cloud metadata endpoints.
- Baseline normal batch endpoint usage and flag deviations in frequency, source account, or target parameters.
- Review sign-up-created accounts for activity against plugin endpoints shortly after creation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://confluence.atlassian.com/display/JIRA/Jira+Server+Security+Advisory+29nd+June+2022 | MitigationVendor Advisory |
| https://jira.atlassian.com/browse/JRASERVER-73863 | Vendor Advisory |
| https://jira.atlassian.com/browse/JSDSERVER-11840 | Vendor Advisory |
| https://confluence.atlassian.com/display/JIRA/Jira+Server+Security+Advisory+29nd+June+2022 | MitigationVendor Advisory |
| https://jira.atlassian.com/browse/JRASERVER-73863 | Vendor Advisory |
| https://jira.atlassian.com/browse/JSDSERVER-11840 | Vendor Advisory |
Track CVE-2022-26135 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-26135), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.