CVE-2022-26135 is a server-side request forgery vulnerability in the Mobile Plugin for Jira bundled with Atlassian Jira Server, Jira Data Center, Jira Service Management Server, and Jira Service Management Data Center. The flaw affects the plugin's batch endpoint, which processes a JSON array of requests server-side. According to the provided content, the vulnerable code path in BatchServiceImpl.java constructs request URLs using URI.create(this.jiraBaseUrls.baseUrl() + path). By supplying an attacker-controlled path containing an @-based authority confusion pattern, such as a value that causes the HTTP client to interpret the portion before @ as userinfo and the portion after @ as the destination host, an authenticated attacker can cause the Jira server to issue outbound requests to attacker-selected internal or external targets. The SSRF primitive is described as full-read and supports arbitrary HTTP methods, headers, and body content, with up to five concurrent requests through the batch API. Affected versions are Jira Server/Data Center 8.0.0 before 8.13.22, 8.14.0 before 8.20.10, and 8.21.0 before 8.22.4; and Jira Service Management Server/Data Center 4.0.0 before 4.13.22, 4.14.0 before 4.20.10, and 4.21.0 before 4.22.4. Jira Cloud is not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a working exploit for CVE-2022-26135, a server-side request forgery (SSRF) vulnerability in Atlassian Jira Core and Jira Service Desk. The exploit is implemented in Python (exploit.py) and automates the process of exploiting the SSRF via the /rest/nativemobile/1.0/batch endpoint. It supports both manual and automatic modes: in automatic mode, it attempts to register a new user if open signups are enabled; in manual mode, it uses provided credentials. The exploit allows the attacker to make the Jira server send arbitrary HTTP requests to attacker-specified hosts, which can be used to access internal services or cloud metadata endpoints (such as 169.254.169.254). The repository also includes a README.md with detailed usage instructions and background information, and a requirements.txt listing Python dependencies. The exploit targets Jira Core versions below 8.20.3 and Jira Service Desk versions below 4.20.3-REL-0018.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A server-side request forgery vulnerability in Atlassian Mobile Plugin for Jira affecting Jira Server/Data Center and Jira Service Management Server/Data Center, allowing authenticated attackers to make server-side requests and potentially access internal services or cloud metadata.
A high-severity server-side request forgery (SSRF) vulnerability in Atlassian Jira Server Core (abused via Jira Service Desk’s Signups function) that can be exploited without obtaining credentials, enabling full-read SSRF behavior as described.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.