CVE-2025-22169

Publication date

2025-10-22 16:30:04

Family

atlassian

State

PUBLISHED

Description

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level.