PatchDay Alert

CVE

CVE-2026-41103

0field notes · 1digest CVSS 9.1


Daily digests

The Microsoft SSO Plugin for Jira and Confluence has a broken authentication implementation that lets an unauthenticated attacker escalate privileges remotely. CVSS 9.1. If you use this plugin to federate Atlassian logins through Microsoft, an attacker could bypass auth entirely and gain elevated access to your Jira or Confluence instance.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.