Broken Authentication and Session Management in Crowd Data Center by Atlassian
CVE-2026-21582
8.8HIGH
What is CVE-2026-21582?
A critical vulnerability in Crowd Data Center has been identified, allowing unauthenticated attackers to perform actions as other users through broken authentication and session management practices. This issue was introduced in version 7.2.1, and users are strongly advised to upgrade to version 7.2.2 or later to mitigate the risks associated with this flaw. For details on the upgrade process, please refer to the official release notes or download the latest version from Atlassian's software archive.
Affected Version(s)
Crowd Data Center 7.2.1
Crowd Data Center 7.2.2 to 7.2.3