The vulnerability exists due to missing authorization checks on linked work items within visible epics in the Epic Issues REST API, permitting an authenticated user to read private child issue content from unauthorized projects.
Source: Mitre, NVD
Published: 2026-09-24
Base Score: 4.9
Vector: CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:N
Severity: Medium
Base Score: 6.5
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N