CVE-2025-22174 Details
Description
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.
A vulnerability in Jira Align allows low-privilege users to access certain endpoints that reveal limited sensitive information. For instance, a user with minimal permissions could view portfolio rooms without the necessary authorization. This issue affects Jira Align versions 11.14.0, 11.14.1, 11.15.0, 11.15.1, and 11.16.0.
Users can upgrade to Jira Align version 11.16.1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jira.atlassian.com/browse/JIRAALIGN-8643 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| atlassian jira align | >= 11.14.0, < 11.16.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 24, 2025 | Initial Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 22, 2025 | New CVE Received | [email protected] |