CVE-2026-21582 PUBLISHED

Assigner: atlassian
Reserved: 01.01.2026 Published: 18.08.2026 Updated: 18.08.2026

This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center.

This BASM (Broken Authentication & Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as another user.

<pre>Atlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Crowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2 See the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center from the download center (https://www.atlassian.com/software/crowd/download-archive). This vulnerability was reported via our Penetration Testing program. </pre>

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
CVSS Score: 8.8

Product Status

Vendor Atlassian
Product Crowd Data Center
Versions
  • Version 7.2.1 is affected
  • Version 7.2.2 to 7.2.3 is unaffected

Credits

  • Internal

References

Problem Types

  • BASM (Broken Authentication & Session Management) BASM (Broken Authentication & Session Management)