Security Bulletin: Issue AI Analytics for Jira Data Center Information Disclosure Vulnerabilities

Vendor: Deview Studios
Product: Issue AI Analytics for Jira Data Center
Fixed Versions: 9.1.6, 10.1.6, and 11.1.6
Discoverer: NATO Communications and Information Agency (NCIA)

Summary

Deview Studios has released security updates for Issue AI Analytics for Jira Data Center to address two local information disclosure vulnerabilities.

These issues affect Issue AI Analytics for Jira Data Center versions before 9.1.6, before 10.1.6, and before 11.1.6.

Vendor assessment indicates that exploitation generally requires privileged database or host access. No direct remote unauthenticated attack path has been identified.

Affected Products

The following versions of Issue AI Analytics for Jira Data Center are affected:

  • Versions before 9.1.6
  • Versions before 10.1.6
  • Versions before 11.1.6

Fixed Versions

The vulnerabilities have been addressed in:

  • 9.1.6
  • 10.1.6
  • 11.1.6

Vulnerability Details

CVE-2026-51931: Hard-coded Cryptographic Key in Legacy Proxy Password Encryption

A vulnerability in Issue AI Analytics for Jira Data Center could allow a local attacker to obtain sensitive information through the product’s legacy proxy-password encryption functionality.

This issue is classified as:

  • CVE: CVE-2026-51931
  • CWE: CWE-321 — Hard-coded Cryptographic Key
  • Attack Type: Local
  • Impact: Information Disclosure

Exploitation generally requires privileged database or host access.

CVE-2026-51932: Use of Cryptographically Weak Pseudo-Random Number Generator

A vulnerability in Issue AI Analytics for Jira Data Center could allow a local attacker to obtain sensitive information due to the use of a cryptographically weak pseudo-random number generator.

This issue is classified as:

  • CVE: CVE-2026-51932
  • CWE: CWE-338 — Use of Cryptographically Weak Pseudo-Random Number Generator
  • Attack Type: Local
  • Impact: Information Disclosure

Exploitation generally requires privileged database or host access.

Remediation

Deview Studios recommends that all customers running affected versions of Issue AI Analytics for Jira Data Center upgrade to one of the fixed versions:

  • Upgrade 9.x deployments to 9.1.6 or later
  • Upgrade 10.x deployments to 10.1.6 or later
  • Upgrade 11.x deployments to 11.1.6 or later.
Deview Studios Logo

We extend various collaboration platforms by developing native integrations and applications. Our mission is to create best-in-class productivity tools for small and large businesses.

Recent Posts

 

Contact Us

Copyright © 2022 Deview Studios