← Vulnerability feed

Vulnerability record · CVE-2022-26135 · published 30 June 2022

CVE-2022-26135: Jira Mobile Plugin batch endpoint full-read SSRF

Atlassian · Jira Data Center

The Mobile Plugin for Jira Data Center and Server exposes a batch endpoint that lets a remote, authenticated user trigger a full read server-side request forgery. Because any account, including one created through the sign-up feature, is sufficient, the flaw gives low-privilege users a way to make the Jira server issue requests on their behalf. It affects Jira Server and Data Center 8.0.0 through 8.22.4 and Jira Management/Service Management 4.0.0 through 4.22.4 per the advisory ranges.

6.5 CVSS 3.1 Medium EPSS 72% · top 0.6% CWE-918 · Server-side request forgery (SSRF)
6.5CVSS 3.1 base score, v2 4.0
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.20.10, from version 8.21.0 before 8.22.4. This also affects Jira Management Server and Data Center versions from version 4.0.0 before 4.13.22, from version 4.14.0 before 4.20.10 and from version 4.21.0 before 4.22.4.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw is remotely reachable by any authenticated user with no interaction and carries high confidentiality impact, and EPSS is very high even though it is not in KEV.

What it is

The Mobile Plugin for Jira Data Center and Server exposes a batch endpoint that lets a remote, authenticated user trigger a full read server-side request forgery. Because any account, including one created through the sign-up feature, is sufficient, the flaw gives low-privilege users a way to make the Jira server issue requests on their behalf. It affects Jira Server and Data Center 8.0.0 through 8.22.4 and Jira Management/Service Management 4.0.0 through 4.22.4 per the advisory ranges.

Impact

An attacker gains the ability to read responses from requests the Jira server makes to internal or external systems, exposing internal services and data reachable from the Jira host. There is no integrity or availability impact per the CVSS vector; the loss is confidentiality.

Attack surface

Reached over the network through the Mobile Plugin batch endpoint; the attacker must be authenticated but needs no user interaction. The sign-up feature means an attacker can often obtain the required account themselves.

Exploitation

Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is very high at 0.716 (99.4th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Upgrade Jira Server/Data Center to 8.13.22, 8.20.10, 8.22.4 or later, and Jira Management/Service Management to 4.13.22, 4.20.10, 4.22.4 or later.
  • If immediate patching is not possible, apply the mitigations in Atlassian's 29 June 2022 security advisory, including disabling or restricting the Mobile Plugin.
  • Disable self-sign-up or restrict account creation so unvetted users cannot obtain the authenticated access the flaw requires.
  • Restrict outbound network access from Jira hosts to only required destinations to limit SSRF reach.
  • Audit accounts and remove unused or untrusted users, especially those created via sign-up.

Detection

  • Monitor Jira logs for requests to the Mobile Plugin batch endpoint, particularly unusual or repeated calls from low-privilege accounts.
  • Alert on outbound connections from Jira hosts to internal RFC1918 addresses, loopback, or cloud metadata endpoints.
  • Baseline normal batch endpoint usage and flag deviations in frequency, source account, or target parameters.
  • Review sign-up-created accounts for activity against plugin endpoints shortly after creation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-26135 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-11581Atlassian Jira Server and Data Center server-side template injectionJira Server and Data Center contain a server-side template injection flaw in the ContactAdministrators and SendBulkMail actions. An attacker can inje…KEVEPSS 85%analysed5.3CVE-2021-26086Atlassian Jira Server and Data Center path traversal file readJira Server and Data Center contain a path traversal flaw in the /WEB-INF/web.xml endpoint that lets remote attackers read particular files. The affe…KEVEPSS 100%analysed9.8CVE-2022-26136Atlassian bamboo improper authentication vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps…EPSS 5.4%9.8CVE-2022-0540Atlassian Jira Seraph authentication bypass via crafted HTTP requestJira Server, Data Center and Jira Service Management contain an authentication bypass in the Seraph component, reachable by sending a specially craft…EPSS 88%analysed9.8CVE-2020-36239Atlassian Jira Data Center Ehcache RMI service missing authentication RCEJira Data Center, Jira Core Data Center, Jira Software Data Center and Jira Service Management Data Center exposed an Ehcache RMI network service on …EPSS 50%analysed9.8CVE-2019-13990Softwareag quartz xml external entity (xxe) vulnerabilityinitDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.EPSS 16%9.1CVE-2023-22501Atlassian jira service management improper authentication vulnerabilityAn authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user…EPSS 16%8.8CVE-2024-21683Atlassian Confluence Data Center and Server code injection RCEConfluence Data Center and Server contain a code injection flaw introduced in version 5.2 that allows an authenticated attacker to execute arbitrary …EPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2022-26135), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.