All verified exploits

CVE-2021-26086 Path Traversal via Static Resources

Deterministic critical Jira CISA KEV Added cve-verified-cve-2021-26086

Reads internal configuration files like WEB-INF/web.xml through Jira's semicolon path parameter bypass in static resource serving.

Is your app exploitable through CVE-2021-26086?

Scan your domain free