CVE-2026-21582 (GCVE-0-2026-21582)
Vulnerability from cvelistv5
Published
2026-08-18 22:00
Modified
2026-08-20 18:34
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- BASM (Broken Authentication & Session Management)
Summary
This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center.
This BASM (Broken Authentication & Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as another user.
Atlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
Crowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2
See the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center from the download center (https://www.atlassian.com/software/crowd/download-archive).
This vulnerability was reported via our Penetration Testing program.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Atlassian | Crowd Data Center |
Version: 7.2.1 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-21582",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-20T03:56:07.440214Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-20T18:34:02.178Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Crowd Data Center",
"vendor": "Atlassian",
"versions": [
{
"status": "affected",
"version": "7.2.1"
},
{
"status": "unaffected",
"version": "7.2.2 to 7.2.3"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "Internal"
}
],
"descriptions": [
{
"lang": "en",
"value": "This High severity BASM (Broken Authentication \u0026 Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center.\r\n\r\nThis BASM (Broken Authentication \u0026 Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as another user.\r\n\t\r\n\tAtlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n\t\t\r\n\t\tCrowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2\r\n\t\t\r\n\t\t\r\n\t\r\n\tSee the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center from the download center (https://www.atlassian.com/software/crowd/download-archive). \r\n\t\r\n\tThis vulnerability was reported via our Penetration Testing program."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "BASM (Broken Authentication \u0026 Session Management)",
"lang": "en",
"type": "BASM (Broken Authentication \u0026 Session Management)"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T22:00:00.412Z",
"orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
"shortName": "atlassian"
},
"references": [
{
"url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999768"
},
{
"url": "https://jira.atlassian.com/browse/CWD-6562"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
"assignerShortName": "atlassian",
"cveId": "CVE-2026-21582",
"datePublished": "2026-08-18T22:00:00.412Z",
"dateReserved": "2026-01-01T00:00:40.721Z",
"dateUpdated": "2026-08-20T18:34:02.178Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"vulnerability-lookup:meta": {
"vulnrichment": {
"containers": "{\"cna\": {\"affected\": [{\"vendor\": \"Atlassian\", \"product\": \"Crowd Data Center\", \"versions\": [{\"version\": \"7.2.1\", \"status\": \"affected\"}, {\"version\": \"7.2.2 to 7.2.3\", \"status\": \"unaffected\"}]}], \"descriptions\": [{\"lang\": \"en\", \"value\": \"This High severity BASM (Broken Authentication \u0026 Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center.\\r\\n\\r\\nThis BASM (Broken Authentication \u0026 Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as another user.\\r\\n\\t\\r\\n\\tAtlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\\r\\n\\t\\t\\r\\n\\t\\tCrowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2\\r\\n\\t\\t\\r\\n\\t\\t\\r\\n\\t\\r\\n\\tSee the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center from the download center (https://www.atlassian.com/software/crowd/download-archive). \\r\\n\\t\\r\\n\\tThis vulnerability was reported via our Penetration Testing program.\"}], \"problemTypes\": [{\"descriptions\": [{\"description\": \"BASM (Broken Authentication \u0026 Session Management)\", \"lang\": \"en\", \"type\": \"BASM (Broken Authentication \u0026 Session Management)\"}]}], \"references\": [{\"url\": \"https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999768\"}, {\"url\": \"https://jira.atlassian.com/browse/CWD-6562\"}], \"credits\": [{\"lang\": \"en\", \"value\": \"Internal\"}], \"metrics\": [{\"cvssV4_0\": {\"version\": \"4.0\", \"vectorString\": \"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N\", \"baseScore\": 8.8, \"baseSeverity\": \"HIGH\"}}], \"providerMetadata\": {\"orgId\": \"f08a6ab8-ed46-4c22-8884-d911ccfe3c66\", \"shortName\": \"atlassian\", \"dateUpdated\": \"2026-08-18T22:00:00.412Z\"}}, \"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-21582\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-08-20T03:56:07.440214Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-287\", \"description\": \"CWE-287 Improper Authentication\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-08-20T18:30:40.946Z\"}}]}",
"cveMetadata": "{\"cveId\": \"CVE-2026-21582\", \"assignerOrgId\": \"f08a6ab8-ed46-4c22-8884-d911ccfe3c66\", \"state\": \"PUBLISHED\", \"assignerShortName\": \"atlassian\", \"dateReserved\": \"2026-01-01T00:00:40.721Z\", \"datePublished\": \"2026-08-18T22:00:00.412Z\", \"dateUpdated\": \"2026-08-20T18:34:02.178Z\"}",
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
}
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…