CVE-2025-22169: Medium severity Atlassian Jira Align vulnerability
Published Oct 22, 2025
·Updated
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level.
Affected Software
2 affected components
Atlassian Jira Align
Atlassian Jira Align>=11.14.0<11.16.1
Event History
Oct 22, 2025
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22169?
CVE-2025-22169 is classified as a low-severity vulnerability.
2
How does CVE-2025-22169 affect users of Jira Align?
CVE-2025-22169 allows low-privilege users to access unintended endpoints exposing some sensitive information.
3
How do I fix CVE-2025-22169?
To fix CVE-2025-22169, it is recommended to review user permissions and restrict access to sensitive endpoints.
4
What type of issue is addressed by CVE-2025-22169?
CVE-2025-22169 addresses an authorization issue within Jira Align.
5
Can low-privilege users exploit CVE-2025-22169?
Yes, low-privilege users can exploit CVE-2025-22169 to access information that they should not be able to.