Impact
This vulnerability, assigned CVE-2026-21582, allows an attacker who is not authenticated to impersonate any user in Atlassian Crowd Data Center. The flaw is a classic broken authentication and session management weakness that results in unauthorized execution of actions with the privileges of the victim user. The impact is full privilege escalation; an attacker can perform any operation the compromised account is permitted to do, potentially accessing confidential data or altering system configuration.
Affected Systems
Atlassian Crowd Data Center version 7.2.1 is affected. Atlassian recommends upgrading to version 7.2.2 or later where the issue is fixed. No other versions were listed as affected.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity of the vulnerability. Exploitation requires no authentication, implying that the attack surface is potentially broad. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is any entity able to send requests to the Crowd server, such as internal network traffic or an external attacker with network access if the application is exposed.
OpenCVE Enrichment