Broken Authentication and Session Management in Crowd Data Center by Atlassian
CVE-2026-21582

8.8HIGH

Key Information:

Vendor

Atlassian

Vendor
CVE Published:
18 August 2026

What is CVE-2026-21582?

A critical vulnerability in Crowd Data Center has been identified, allowing unauthenticated attackers to perform actions as other users through broken authentication and session management practices. This issue was introduced in version 7.2.1, and users are strongly advised to upgrade to version 7.2.2 or later to mitigate the risks associated with this flaw. For details on the upgrade process, please refer to the official release notes or download the latest version from Atlassian's software archive.

Affected Version(s)

Crowd Data Center 7.2.1

Crowd Data Center 7.2.2 to 7.2.3

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Internal
.