Improper Authorization in Bamboo Data Center by Atlassian
CVE-2026-21584

7.6HIGH

Key Information:

Vendor

Atlassian

Vendor
CVE Published:
18 August 2026

What is CVE-2026-21584?

An Improper Authorization vulnerability in Bamboo Data Center allows authenticated attackers to exploit unintended access, potentially exposing sensitive resources and functionalities. Attackers may gain access to confidential data or execute arbitrary code. Atlassian has advised users to upgrade to secure versions 10.2.22 or higher for 10.2 and 12.1.10 for 12.1 to mitigate this issue. Details can be found in the release notes.

Affected Version(s)

Bamboo Data Center 12.1.0 to 12.1.9

Bamboo Data Center 12.0.0 to 12.0.2

Bamboo Data Center 11.0.0 to 11.0.8

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.