CVE-2025-22176: Medium severity Atlassian Jira Align vulnerability
Published Oct 22, 2025
·Updated
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items.
Affected Software
2 affected components
Atlassian Jira Align
Atlassian Jira Align>=11.14.0<11.16.1
Event History
Oct 22, 2025
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22176?
CVE-2025-22176 has been classified as a low-severity authorization issue.
2
How do I fix CVE-2025-22176?
To mitigate CVE-2025-22176, ensure that user permissions are properly configured and limit access to sensitive endpoints.
3
What type of information can be accessed due to CVE-2025-22176?
A low-privilege user can access unintended endpoints that may disclose a small amount of sensitive information, such as audit log items.
4
Which software is affected by CVE-2025-22176?
Atlassian Jira Align is the software that is affected by CVE-2025-22176.
5
Who is at risk due to CVE-2025-22176?
Low-privilege users of Atlassian Jira Align are at risk of accessing unauthorized information due to CVE-2025-22176.